--------[ EVEREST Ultimate Edition 2006 (c) 2003-2006 Lavalys, Inc. ]---------------------------------------------------

    Version                                           EVEREST v3.01.652
    Benchmark Module                                  2.0.160.0
    Homepage                                          http://www.lavalys.com/
    Report Type                                       Report Wizard
    Computer                                          WEBERSERVER
    Generator                                         Administrator
    Operating System                                  Microsoft Windows Small Business Server 2003, Standard Edition 5.2.3790 (Win2003 Retail)
    Date                                              2008-03-29
    Time                                              10:58


--------[ Summary ]-----------------------------------------------------------------------------------------------------

    Computer:
      Computer Type                                     ACPI Uniprocessor PC
      Operating System                                  Microsoft Windows Small Business Server 2003, Standard Edition
      OS Service Pack                                   Service Pack 2
      Internet Explorer                                 6.0.3790.3959
      DirectX                                           4.09.00.0904 (DirectX 9.0c)
      Computer Name                                     WEBERSERVER
      User Name                                         Administrator
      Logon Domain                                      WEBERSERVER
      Date / Time                                       2008-03-29 / 10:56

    Motherboard:
      CPU Type                                          Unknown, 2200 MHz
      Motherboard Name                                  Unknown
      Motherboard Chipset                               Unknown
      System Memory                                     896 MB
      BIOS Type                                         Award (09/07/07)
      Communication Port                                Communications Port (COM1)
      Communication Port                                ECP Printer Port (LPT1)

    Display:
      Video Adapter                                     ATI Radeon Xpress 1250  (320 MB)
      Video Adapter                                     ATI Radeon Xpress 1250  (320 MB)
      3D Accelerator                                    ATI RS690

    Multimedia:
      Audio Adapter                                     Microsoft RDP Audio Driver

    Storage:
      IDE Controller                                    ATI IDE Controller
      IDE Controller                                    Standard Dual Channel PCI IDE Controller
      Disk Drive                                        Maxtor 6L250S0  (250 GB, 7200 RPM, SATA)
      Disk Drive                                        WDC WD5000AACS-00ZUB0  (465 GB, IDE)
      SMART Hard Disks Status                           OK

    Partitions:
      C: (NTFS)                                         20481 MB (16420 MB free)
      D: (NTFS)                                         456448 MB (256804 MB free)
      Total Size                                        465.8 GB (266.8 GB free)

    Network:
      Primary IP Address                                192.168.0.11
      Primary MAC Address                               00-1D-60-2D-26-64
      Network Adapter                                   Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC  (192.168.0.11)

    Peripherals:
      USB1 Controller                                   ATI SB600 - USB Controller
      USB1 Controller                                   ATI SB600 - USB Controller
      USB1 Controller                                   ATI SB600 - USB Controller
      USB1 Controller                                   ATI SB600 - USB Controller
      USB1 Controller                                   ATI SB600 - USB Controller
      USB2 Controller                                   ATI SB600 - USB 2.0 Controller

    DMI:
      DMI BIOS Vendor                                   Phoenix Technologies, LTD
      DMI BIOS Version                                  ASUS M2A-VM ACPI BIOS Revision 1201
      DMI System Manufacturer                           System manufacturer
      DMI System Product                                System Product Name
      DMI System Version                                System Version
      DMI System Serial Number                          System Serial Number
      DMI System UUID                                   B7116F33-3D536071-818CBEAE-42CFA7F5
      DMI Motherboard Manufacturer                      ASUSTeK Computer INC.
      DMI Motherboard Product                           M2A-VM
      DMI Motherboard Version                           1.XX
      DMI Motherboard Serial Number                     123456789000
      DMI Chassis Manufacturer                          Chassis Manufacture
      DMI Chassis Version                               Chassis Version
      DMI Chassis Serial Number                         EVAL
      DMI Chassis Asset Tag                             123456789000
      DMI Chassis Type                                  Desktop Case
      DMI Total / Free Memory Sockets                   4 / 2


--------[ Computer Name ]-----------------------------------------------------------------------------------------------

    Computer Comment          Logical   
    NetBIOS Name              Logical   WEBERSERVER
    DNS Host Name             Logical   weberserver
    DNS Domain Name           Logical   
    Fully Qualified DNS Name  Logical   weberserver
    NetBIOS Name              Physical  WEBERSERVER
    DNS Host Name             Physical  weberserver
    DNS Domain Name           Physical  
    Fully Qualified DNS Name  Physical  weberserver


--------[ Operating System ]--------------------------------------------------------------------------------------------

    Operating System Properties:
      OS Name                                           Microsoft Windows Small Business Server 2003, Standard Edition
      OS Code Name                                      Whistler Server
      OS Language                                       English (United States)
      OS Kernel Type                                    Uniprocessor Free
      OS Version                                        5.2.3790 (Win2003 Retail)
      OS Service Pack                                   Service Pack 2
      OS Installation Date                              1/15/2008
      OS Root                                           C:\WINDOWS

    License Information:
      Registered Owner                                  Windows Home Server User
      Registered Organization                           Family
      Licensed Processors                               2
      Product ID                                        78495-OEM-4239307-00002
      Product Key                                       P2H7J-VDDX2-KKVFY-TVWKK-F43JD
      Product Activation (WPA)                          Required

    Current Session:
      Computer Name                                     WEBERSERVER
      User Name                                         Administrator
      Logon Domain                                      WEBERSERVER
      UpTime                                            62131 sec (0 days, 17 hours, 15 min, 31 sec)

    Components Version:
      Common Controls                                   6.00
      Internet Explorer                                 6.0.3790.3959
      Internet Explorer Updates                         SP2
      Outlook Express                                   6.00.3790.3959 (srv03_sp2_rtm.070216-1710)
      Windows Media Player                              10.00.00.3997
      Windows Messenger                                 -
      MSN Messenger                                     -
      Internet Information Services (IIS)               6.0
      .NET Framework                                    2.0.50727.832 (QFE.050727-8300)
      Novell Client                                     -
      DirectX                                           4.09.00.0904 (DirectX 9.0c)
      OpenGL                                            5.2.3790.3959 (srv03_sp2_rtm.070216-1710)
      ASPI                                              -

    Operating System Features:
      Debug Version                                     No
      DBCS Version                                      No
      Domain Controller                                 No
      Security Present                                  No
      Network Present                                   Yes
      Remote Session                                    Yes
      Safe Mode                                         No
      Slow Processor                                    No
      Terminal Services                                 Yes


--------[ Processes ]---------------------------------------------------------------------------------------------------

    cFosSpeed.exe            C:\Program Files\cFosSpeed\cFosSpeed.exe                                      32-bit         7896 KB          3380 KB
    ctfmon.exe               C:\WINDOWS\system32\ctfmon.exe                                                32-bit         3156 KB           676 KB
    demigrator.exe           C:\Program Files\Windows Home Server\demigrator.exe                           32-bit        10828 KB         23728 KB
    dmadmin.exe              C:\WINDOWS\System32\dmadmin.exe                                               32-bit          676 KB          2516 KB
    dms_helper.exe           C:\Program Files\DiXiM Media Server\dms_helper.exe                            32-bit         4540 KB          1744 KB
    dmsf.exe                 C:\Program Files\DiXiM Media Server\dmsf.exe                                  32-bit        55076 KB         78564 KB
    EVEREST.bin              D:\shares\Software\Tools\EVEREST\EVEREST.bin                                  32-bit        26188 KB         18868 KB
    Explorer.EXE             C:\WINDOWS\Explorer.EXE                                                       32-bit        12612 KB          7324 KB
    inetinfo.exe             C:\WINDOWS\system32\inetsrv\inetinfo.exe                                      32-bit         2500 KB          3384 KB
    lsass.exe                C:\WINDOWS\system32\lsass.exe                                                 32-bit         4664 KB          7072 KB
    pdl.exe                  C:\Program Files\Windows Home Server\pdl.exe                                  32-bit          880 KB           836 KB
    qsm.exe                  C:\Program Files\Windows Home Server\qsm.exe                                  32-bit         3176 KB          3372 KB
    rdpclip.exe              C:\WINDOWS\system32\rdpclip.exe                                               32-bit         3604 KB          1128 KB
    services.exe             C:\WINDOWS\system32\services.exe                                              32-bit         2656 KB          1628 KB
    smss.exe                 C:\WINDOWS\System32\smss.exe                                                  32-bit          276 KB           168 KB
    spd.exe                  C:\Program Files\cFosSpeed\spd.exe                                            32-bit         3328 KB          4004 KB
    spoolsv.exe              C:\WINDOWS\system32\spoolsv.exe                                               32-bit         1692 KB          3372 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit          340 KB           680 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit         1500 KB          2940 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit         2152 KB          2512 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit         4116 KB          3028 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit         3528 KB           988 KB
    svchost.exe              C:\WINDOWS\system32\svchost.exe                                               32-bit         1232 KB           984 KB
    svchost.exe              C:\WINDOWS\System32\svchost.exe                                               32-bit        23556 KB         23748 KB
    TransportService.exe     C:\Program Files\Windows Home Server\TransportService.exe                     32-bit         5540 KB          6324 KB
    uTorrent.exe             C:\Program Files\uTorrent\uTorrent.exe                                        32-bit        14640 KB         14784 KB
    vds.exe                  C:\WINDOWS\System32\vds.exe                                                   32-bit          776 KB          3752 KB
    vssvc.exe                C:\WINDOWS\System32\vssvc.exe                                                 32-bit         4076 KB          1232 KB
    whsarch.exe              C:\Program Files\Windows Home Server\whsarch.exe                              32-bit         1748 KB           804 KB
    whsbackup.exe            C:\Program Files\Windows Home Server\whsbackup.exe                            32-bit         3680 KB          3336 KB
    winlogon.exe             C:\WINDOWS\system32\winlogon.exe                                              32-bit         1624 KB          3596 KB
    winlogon.exe             C:\WINDOWS\system32\winlogon.exe                                              32-bit         7048 KB          8144 KB
    wuauclt.exe              C:\WINDOWS\system32\wuauclt.exe                                               32-bit         3652 KB          2120 KB
    xplorer2_lite.exe        C:\Program Files\xplorer2_lite\xplorer2_lite.exe                              32-bit         9392 KB          4416 KB


--------[ System Drivers ]----------------------------------------------------------------------------------------------

    Abiosdsk         Abiosdsk                                                                                                       Kernel Driver                   Stopped
    ACPI             Microsoft ACPI Driver                                                   ACPI.sys              5.2.3790.3959    Kernel Driver                   Running
    ACPIEC           ACPIEC                                                                                                         Kernel Driver                   Stopped
    adpu160m         adpu160m                                                                                                       Kernel Driver                   Stopped
    adpu320          adpu320                                                                                                        Kernel Driver                   Stopped
    afcnt            afcnt                                                                                                          Kernel Driver                   Stopped
    AFD              AFD                                                                     afd.sys               5.2.3790.3959    Kernel Driver                   Running
    aic78u2          aic78u2                                                                                                        Kernel Driver                   Stopped
    aic78xx          aic78xx                                                                                                        Kernel Driver                   Stopped
    AliIde           AliIde                                                                                                         Kernel Driver                   Stopped
    AmdIde           AmdIde                                                                                                         Kernel Driver                   Stopped
    AmdK8            AMD Processor Driver                                                    AmdK8.sys             1.3.2.0          Kernel Driver                   Running
    arc              arc                                                                                                            Kernel Driver                   Stopped
    AsyncMac         RAS Asynchronous Media Driver                                           asyncmac.sys          5.2.3790.0       Kernel Driver                   Stopped
    atapi            Standard IDE/ESDI Hard Disk Controller                                  atapi.sys             5.2.3790.3959    Kernel Driver                   Running
    Atdisk           Atdisk                                                                                                         Kernel Driver                   Stopped
    ati2mtag         ati2mtag                                                                ati2mtag.sys          6.14.10.6666     Kernel Driver                   Running
    Atmarpc          ATM ARP Client Protocol                                                 atmarpc.sys           5.2.3790.3959    Kernel Driver                   Stopped
    audstub          Audio Stub Driver                                                       audstub.sys           5.2.3790.0       Kernel Driver                   Running
    Beep             Beep                                                                                                           Kernel Driver                   Running
    cbidf2k          cbidf2k                                                                                                        Kernel Driver                   Stopped
    cd20xrnt         cd20xrnt                                                                                                       Kernel Driver                   Stopped
    Cdfs             Cdfs                                                                                                           File System Driver              Stopped
    Cdrom            CD-ROM Driver                                                           cdrom.sys             5.2.3790.3959    Kernel Driver                   Stopped
    cFosSpeed        cFosSpeed Miniport                                                      cfosspeed.sys         4.20.1389.0      Kernel Driver                   Running
    Changer          Changer                                                                                                        Kernel Driver                   Stopped
    ClusDisk         Cluster Disk Driver                                                     ClusDisk.sys          5.2.3790.3959    Kernel Driver                   Stopped
    CmdIde           CmdIde                                                                                                         Kernel Driver                   Stopped
    Cpqarray         Cpqarray                                                                                                       Kernel Driver                   Stopped
    cpqarry2         cpqarry2                                                                                                       Kernel Driver                   Stopped
    cpqcissm         cpqcissm                                                                                                       Kernel Driver                   Stopped
    cpqfcalm         cpqfcalm                                                                                                       Kernel Driver                   Stopped
    crcdisk          CRC Disk Filter Driver                                                  crcdisk.sys           5.2.3790.3959    Kernel Driver                   Running
    dac960nt         dac960nt                                                                                                       Kernel Driver                   Stopped
    DEFilter         DEFilter                                                                DEfilter.sys          6.0.1500.8       File System Driver              Running
    dellcerc         dellcerc                                                                                                       Kernel Driver                   Stopped
    DfsDriver        DfsDriver                                                               Dfs.sys               5.2.3790.3959    File System Driver              Running
    Disk             Disk Driver                                                             disk.sys              5.2.3790.3959    Kernel Driver                   Running
    dmboot           dmboot                                                                  dmboot.sys            5.2.3790.3959    Kernel Driver                   Stopped
    dmio             Logical Disk Manager Driver                                             dmio.sys              5.2.3790.3959    Kernel Driver                   Running
    dmload           dmload                                                                  dmload.sys            5.2.3790.0       Kernel Driver                   Running
    dpti2o           dpti2o                                                                                                         Kernel Driver                   Stopped
    elxstor          elxstor                                                                                                        Kernel Driver                   Stopped
    EverestDriver    Lavalys EVEREST Kernel Driver                                           kerneld.wnt                            Kernel Driver                   Running
    Fastfat          Fastfat                                                                                                        File System Driver              Stopped
    Fdc              Fdc                                                                                                            Kernel Driver                   Stopped
    Fips             Fips                                                                                                           Kernel Driver                   Running
    Flpydisk         Flpydisk                                                                                                       Kernel Driver                   Stopped
    FltMgr           FltMgr                                                                  fltMgr.sys            5.2.3790.3959    File System Driver              Running
    Ftdisk           Volume Manager Driver                                                   ftdisk.sys            5.2.3790.3959    Kernel Driver                   Running
    Gpc              Generic Packet Classifier                                               msgpc.sys             5.2.3790.3959    Kernel Driver                   Running
    HDAudBus         Microsoft UAA Bus Driver for High Definition Audio                      HDAudBus.sys          5.10.1.5013      Kernel Driver                   Stopped
    hpcisss          hpcisss                                                                                                        Kernel Driver                   Stopped
    hpn              hpn                                                                                                            Kernel Driver                   Stopped
    hpt3xx           hpt3xx                                                                                                         Kernel Driver                   Stopped
    HTTP             HTTP                                                                    HTTP.sys              5.2.3790.3959    Kernel Driver                   Running
    i2omgmt          i2omgmt                                                                                                        Kernel Driver                   Stopped
    i2omp            i2omp                                                                                                          Kernel Driver                   Stopped
    i8042prt         i8042 Keyboard and PS/2 Mouse Port Driver                               i8042prt.sys          5.2.3790.3959    Kernel Driver                   Stopped
    iirsp            iirsp                                                                                                          Kernel Driver                   Stopped
    imapi            CD-Burning Filter Driver                                                imapi.sys             5.2.3790.3959    Kernel Driver                   Stopped
    IntelIde         IntelIde                                                                                                       Kernel Driver                   Stopped
    Ip6Fw            IPv6 Windows Firewall Driver                                            Ip6Fw.sys             5.2.3790.3959    Kernel Driver                   Stopped
    IpFilterDriver   IP Traffic Filter Driver                                                ipfltdrv.sys          5.2.3790.3959    Kernel Driver                   Stopped
    IpInIp           IP in IP Tunnel Driver                                                  ipinip.sys                             Kernel Driver                   Stopped
    IpNat            IP Network Address Translator                                           ipnat.sys             5.2.3790.3959    Kernel Driver                   Running
    IPSec            IPSEC driver                                                            ipsec.sys             5.2.3790.3959    Kernel Driver                   Running
    ipsraidn         ipsraidn                                                                                                       Kernel Driver                   Stopped
    IRENUM           IR Enumerator Service                                                   irenum.sys            5.2.3790.3959    Kernel Driver                   Stopped
    isapnp           PnP ISA/EISA Bus Driver                                                 isapnp.sys            5.2.3790.3959    Kernel Driver                   Running
    Kbdclass         Keyboard Class Driver                                                   kbdclass.sys          5.2.3790.3959    Kernel Driver                   Running
    KSecDD           KSecDD                                                                                                         Kernel Driver                   Running
    lp6nds35         lp6nds35                                                                                                       Kernel Driver                   Stopped
    mnmdd            mnmdd                                                                                                          Kernel Driver                   Running
    Modem            Modem                                                                                                          Kernel Driver                   Stopped
    Mouclass         Mouse Class Driver                                                      mouclass.sys          5.2.3790.0       Kernel Driver                   Running
    MountMgr         Mount Point Manager                                                                                            Kernel Driver                   Running
    mraid35x         mraid35x                                                                                                       Kernel Driver                   Stopped
    MRxDAV           WebDav Client Redirector                                                mrxdav.sys            5.2.3790.4206    File System Driver              Stopped
    MRxSmb           MRxSmb                                                                  mrxsmb.sys            5.2.3790.3959    File System Driver              Running
    Msfs             Msfs                                                                                                           File System Driver              Running
    mssmbios         Microsoft System Management BIOS Driver                                 mssmbios.sys          5.2.3790.3959    Kernel Driver                   Running
    Mup              Mup                                                                                                            File System Driver              Running
    NDIS             NDIS System Driver                                                                                             Kernel Driver                   Running
    NdisTapi         Remote Access NDIS TAPI Driver                                          ndistapi.sys          5.2.3790.3959    Kernel Driver                   Running
    Ndisuio          NDIS Usermode I/O Protocol                                              ndisuio.sys           5.2.3790.3959    Kernel Driver                   Running
    NdisWan          Remote Access NDIS WAN Driver                                           ndiswan.sys           5.2.3790.3959    Kernel Driver                   Running
    NDProxy          NDIS Proxy                                                                                                     Kernel Driver                   Running
    NetBIOS          NetBIOS Interface                                                       netbios.sys           5.2.3790.3959    File System Driver              Running
    NetBT            NetBios over Tcpip                                                      netbt.sys             5.2.3790.3959    Kernel Driver                   Running
    nfrd960          nfrd960                                                                                                        Kernel Driver                   Stopped
    Npfs             Npfs                                                                                                           File System Driver              Running
    Ntfs             Ntfs                                                                                                           File System Driver              Running
    Null             Null                                                                                                           Kernel Driver                   Running
    Parport          Parallel port driver                                                    parport.sys           5.2.3790.3959    Kernel Driver                   Running
    PartMgr          Partition Manager                                                                                              Kernel Driver                   Running
    Parvdm           Parvdm                                                                  parvdm.sys            5.2.3790.0       Kernel Driver                   Running
    PCI              PCI Bus Driver                                                          pci.sys               5.2.3790.3959    Kernel Driver                   Running
    PCIIde           PCIIde                                                                  pciide.sys            5.2.3790.0       Kernel Driver                   Running
    Pcmcia           Pcmcia                                                                                                         Kernel Driver                   Stopped
    PDCOMP           PDCOMP                                                                                                         Kernel Driver                   Stopped
    PDFRAME          PDFRAME                                                                                                        Kernel Driver                   Stopped
    PDRELI           PDRELI                                                                                                         Kernel Driver                   Stopped
    PDRFRAME         PDRFRAME                                                                                                       Kernel Driver                   Stopped
    perc2            perc2                                                                                                          Kernel Driver                   Stopped
    perc2hib         perc2hib                                                                                                       Kernel Driver                   Stopped
    PptpMiniport     WAN Miniport (PPTP)                                                     raspptp.sys           5.2.3790.3959    Kernel Driver                   Running
    Processor        Processor Driver                                                        processr.sys          5.2.3790.3959    Kernel Driver                   Stopped
    Ptilink          Direct Parallel Link Driver                                             ptilink.sys           1.1.0.0          Kernel Driver                   Running
    ql1080           ql1080                                                                                                         Kernel Driver                   Stopped
    Ql10wnt          Ql10wnt                                                                                                        Kernel Driver                   Stopped
    ql12160          ql12160                                                                                                        Kernel Driver                   Stopped
    ql1240           ql1240                                                                                                         Kernel Driver                   Stopped
    ql1280           ql1280                                                                                                         Kernel Driver                   Stopped
    ql2100           ql2100                                                                                                         Kernel Driver                   Stopped
    ql2200           ql2200                                                                                                         Kernel Driver                   Stopped
    ql2300           ql2300                                                                                                         Kernel Driver                   Stopped
    RasAcd           Remote Access Auto Connection Driver                                    rasacd.sys            5.2.3790.0       Kernel Driver                   Running
    Rasl2tp          WAN Miniport (L2TP)                                                     rasl2tp.sys           5.2.3790.3959    Kernel Driver                   Running
    RasPppoe         Remote Access PPPOE Driver                                              raspppoe.sys          5.2.3790.3959    Kernel Driver                   Running
    Raspti           Direct Parallel                                                         raspti.sys            5.2.3790.3959    Kernel Driver                   Running
    Rdbss            Rdbss                                                                   rdbss.sys             5.2.3790.3959    File System Driver              Running
    RDPCDD           RDPCDD                                                                  RDPCDD.sys            5.2.3790.0       Kernel Driver                   Running
    rdpdr            Terminal Server Device Redirector Driver                                rdpdr.sys             5.2.3790.3959    Kernel Driver                   Running
    RDPWD            RDPWD                                                                                                          Kernel Driver                   Running
    redbook          Digital CD Audio Playback Filter Driver                                 redbook.sys           5.2.3790.3959    Kernel Driver                   Stopped
    RTLE8023xp       Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver                     Rtenicxp.sys          5.658.814.2006   Kernel Driver                   Running
    Secdrv           Secdrv                                                                  secdrv.sys            4.3.86.0         Kernel Driver                   Stopped
    serenum          Serenum Filter Driver                                                   serenum.sys           5.2.3790.3959    Kernel Driver                   Running
    Serial           Serial port driver                                                      serial.sys            5.2.3790.3959    Kernel Driver                   Running
    Sfloppy          Sfloppy                                                                                                        Kernel Driver                   Stopped
    Simbad           Simbad                                                                                                         Kernel Driver                   Stopped
    Srv              Srv                                                                     srv.sys               5.2.3790.3959    File System Driver              Running
    swenum           Software Bus Driver                                                     swenum.sys            5.3.3790.3959    Kernel Driver                   Running
    sym_hi           sym_hi                                                                                                         Kernel Driver                   Stopped
    sym_u3           sym_u3                                                                                                         Kernel Driver                   Stopped
    symc810          symc810                                                                                                        Kernel Driver                   Stopped
    symc8xx          symc8xx                                                                                                        Kernel Driver                   Stopped
    symmpi           symmpi                                                                                                         Kernel Driver                   Stopped
    Tcpip            TCP/IP Protocol Driver                                                  tcpip.sys             5.2.3790.4179    Kernel Driver                   Running
    TDPIPE           TDPIPE                                                                                                         Kernel Driver                   Stopped
    TDTCP            TDTCP                                                                                                          Kernel Driver                   Running
    TermDD           Terminal Device Driver                                                  termdd.sys            5.2.3790.3959    Kernel Driver                   Running
    TosIde           TosIde                                                                                                         Kernel Driver                   Stopped
    Udfs             Udfs                                                                                                           File System Driver              Stopped
    ultra            ultra                                                                                                          Kernel Driver                   Stopped
    Update           Microcode Update Driver                                                 update.sys            5.2.3790.3959    Kernel Driver                   Running
    usbehci          Microsoft USB 2.0 Enhanced Host Controller Miniport Driver              usbehci.sys           5.2.3790.3959    Kernel Driver                   Running
    usbhub           USB2 Enabled Hub                                                        usbhub.sys            5.2.3790.3959    Kernel Driver                   Running
    usbohci          Microsoft USB Open Host Controller Miniport Driver                      usbohci.sys           5.2.3790.3959    Kernel Driver                   Running
    USBSTOR          USB Mass Storage Driver                                                 USBSTOR.SYS           5.2.3790.3959    Kernel Driver                   Stopped
    vga              vga                                                                     vgapnp.sys            5.2.3790.3959    Kernel Driver                   Stopped
    VgaSave          VGA Display Controller.                                                 vga.sys               5.2.3790.3959    Kernel Driver                   Running
    ViaIde           ViaIde                                                                                                         Kernel Driver                   Stopped
    VolSnap          Storage volumes                                                         volsnap.sys           5.2.3790.3959    Kernel Driver                   Running
    Wanarp           Remote Access IP ARP Driver                                             wanarp.sys            5.2.3790.3959    Kernel Driver                   Running
    WDICA            WDICA                                                                                                          Kernel Driver                   Stopped
    WLBS             Network Load Balancing                                                  wlbs.sys              5.2.3790.3959    Kernel Driver                   Stopped


--------[ Services ]----------------------------------------------------------------------------------------------------

    AeLookupSvc                        Application Experience Lookup Service                                   svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Alerter                            Alerter                                                                 svchost.exe           5.2.3790.3959    Share Process        Stopped               NT AUTHORITY\LocalService
    ALG                                Application Layer Gateway Service                                       alg.exe               5.2.3790.3959    Own Process          Running               NT AUTHORITY\LocalService
    AppMgmt                            Application Management                                                  svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    aspnet_state                       ASP.NET State Service                                                   aspnet_state.exe      2.0.50727.832    Own Process          Stopped               NT AUTHORITY\NetworkService
    Ati HotKey Poller                  Ati HotKey Poller                                                       Ati2evxx.exe          6.14.10.4158     Own Process          Stopped               LocalSystem
    AudioSrv                           Windows Audio                                                           svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    BITS                               Background Intelligent Transfer Service                                 svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Browser                            Computer Browser                                                        svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    cFosSpeedS                         cFosSpeed System Service                                                spd.exe               4.20.1389.0      Own Process          Running               LocalSystem
    CiSvc                              Indexing Service                                                        cisvc.exe             5.2.3790.3959    Share Process        Stopped               LocalSystem
    ClipSrv                            ClipBook                                                                clipsrv.exe           5.2.3790.0       Own Process          Stopped               LocalSystem
    clr_optimization_v2.0.50727_32     .NET Runtime Optimization Service v2.0.50727_X86                        mscorsvw.exe          2.0.50727.832    Own Process          Stopped               LocalSystem
    COMSysApp                          COM+ System Application                                                 dllhost.exe           5.2.3790.3959    Own Process          Stopped               LocalSystem
    CryptSvc                           Cryptographic Services                                                  svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    DcomLaunch                         DCOM Server Process Launcher                                            svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    DDNSS                              Windows Live Custom Domains Service                                     ddnss.exe             6.0.1500.8       Own Process          Stopped               LocalSystem
    Dfs                                Distributed File System                                                 Dfssvc.exe            5.2.3790.3959    Own Process          Stopped               LocalSystem
    Dhcp                               DHCP Client                                                             svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\NetworkService
    DiXiM Media Server                 DiXiM Media Server                                                      dmsf.exe              2.3.11.0         Own Process          Running               LocalSystem
    dmadmin                            Logical Disk Manager Administrative Service                             dmadmin.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    dmserver                           Logical Disk Manager                                                    svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Dnscache                           DNS Client                                                              svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\NetworkService
    DriveExtenderMigrator              Drive Extender Migrator Service                                         demigrator.exe        6.0.1500.6       Own Process          Running               LocalSystem
    ERSvc                              Error Reporting Service                                                 svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Eventlog                           Event Log                                                               services.exe          5.2.3790.3959    Share Process        Running               LocalSystem
    EventSystem                        COM+ Event System                                                       svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    helpsvc                            Help and Support                                                        svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    HidServ                            Human Interface Device Access                                           svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    HTTPFilter                         HTTP SSL                                                                lsass.exe             5.2.3790.0       Share Process        Running               LocalSystem
    IISADMIN                           IIS Admin Service                                                       inetinfo.exe          6.0.3790.3959    Share Process        Running               LocalSystem
    ImapiService                       IMAPI CD-Burning COM Service                                            imapi.exe             5.2.3790.3959    Own Process          Stopped               LocalSystem
    IsmServ                            Intersite Messaging                                                     ismserv.exe           5.2.3790.3959    Own Process          Stopped               LocalSystem
    kdc                                Kerberos Key Distribution Center                                        lsass.exe             5.2.3790.0       Share Process        Stopped               LocalSystem
    lanmanserver                       Server                                                                  svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    lanmanworkstation                  Workstation                                                             svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    LicenseService                     License Logging                                                         llssrv.exe            5.2.3790.3959    Own Process          Running               NT AUTHORITY\NetworkService
    LmHosts                            TCP/IP NetBIOS Helper                                                   svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\LocalService
    Messenger                          Messenger                                                               svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    mnmsrvc                            NetMeeting Remote Desktop Sharing                                       mnmsrvc.exe           5.2.3790.3959    Own Process          Stopped               LocalSystem
    MSDTC                              Distributed Transaction Coordinator                                     msdtc.exe             2001.12.4720.3959  Own Process          Running               NT AUTHORITY\NetworkService
    MSIServer                          Windows Installer                                                       msiexec.exe           3.1.4000.3959    Share Process        Stopped               LocalSystem
    NetDDE                             Network DDE                                                             netdde.exe            5.2.3790.3959    Share Process        Stopped               LocalSystem
    NetDDEdsdm                         Network DDE DSDM                                                        netdde.exe            5.2.3790.3959    Share Process        Stopped               LocalSystem
    Netlogon                           Net Logon                                                               lsass.exe             5.2.3790.0       Share Process        Stopped               LocalSystem
    Netman                             Network Connections                                                     svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Nla                                Network Location Awareness (NLA)                                        svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    NtFrs                              File Replication                                                        ntfrs.exe             5.2.3790.3959    Own Process          Stopped               LocalSystem
    NtLmSsp                            NT LM Security Support Provider                                         lsass.exe             5.2.3790.0       Share Process        Stopped               LocalSystem
    NtmsSvc                            Removable Storage                                                       svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    pdl                                Windows Home Server Drive Letter Service                                pdl.exe               6.0.1500.6       Own Process          Running               LocalSystem
    PlugPlay                           Plug and Play                                                           services.exe          5.2.3790.3959    Share Process        Running               LocalSystem
    PolicyAgent                        IPSEC Services                                                          lsass.exe             5.2.3790.0       Share Process        Stopped               LocalSystem
    PortForwarding                     Windows Home Server Port Forwarding                                     portfwd.exe           6.0.1500.6       Own Process          Stopped               LocalSystem
    ProtectedStorage                   Protected Storage                                                       lsass.exe             5.2.3790.0       Share Process        Running               LocalSystem
    QSM                                Windows Home Server Storage Manager                                     qsm.exe               6.0.1500.8       Own Process          Running               LocalSystem
    RasAuto                            Remote Access Auto Connection Manager                                   svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    RasMan                             Remote Access Connection Manager                                        svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    RDSessMgr                          Remote Desktop Help Session Manager                                     sessmgr.exe           5.2.3790.3959    Own Process          Stopped               LocalSystem
    RemoteAccess                       Routing and Remote Access                                               svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    RemoteRegistry                     Remote Registry                                                         svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\LocalService
    RpcLocator                         Remote Procedure Call (RPC) Locator                                     locator.exe           5.2.3790.0       Own Process          Stopped               NT AUTHORITY\NetworkService
    RpcSs                              Remote Procedure Call (RPC)                                             svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\NetworkService
    RSoPProv                           Resultant Set of Policy Provider                                        RSoPProv.exe          5.2.3790.3959    Share Process        Stopped               LocalSystem
    sacsvr                             Special Administration Console Helper                                   svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    SamSs                              Security Accounts Manager                                               lsass.exe             5.2.3790.0       Share Process        Running               LocalSystem
    SBCore                             SBCore Service                                                                                                 Own Process          Running               LocalSystem
    SCardSvr                           Smart Card                                                              SCardSvr.exe          5.2.3790.3959    Share Process        Stopped               NT AUTHORITY\LocalService
    Schedule                           Task Scheduler                                                          svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    seclogon                           Secondary Logon                                                         svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    SENS                               System Event Notification                                               svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    SharedAccess                       Windows Firewall/Internet Connection Sharing (ICS)                      svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    ShellHWDetection                   Shell Hardware Detection                                                svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Spooler                            Print Spooler                                                           spoolsv.exe           5.2.3790.3959    Own Process          Running               LocalSystem
    SSDPSRV                            SSDP Discovery Service                                                  svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\LocalService
    stisvc                             Windows Image Acquisition (WIA)                                         svchost.exe           5.2.3790.3959    Share Process        Stopped               NT AUTHORITY\LocalService
    swprv                              Microsoft Software Shadow Copy Provider                                 svchost.exe           5.2.3790.3959    Own Process          Running               LocalSystem
    SysmonLog                          Performance Logs and Alerts                                             smlogsvc.exe          5.2.3790.3959    Own Process          Stopped               NT Authority\NetworkService
    TapiSrv                            Telephony                                                               svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    TermService                        Terminal Services                                                       svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Themes                             Themes                                                                  svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    TlntSvr                            Telnet                                                                  tlntsvr.exe           5.2.3790.3959    Own Process          Stopped               NT AUTHORITY\LocalService
    TrkSvr                             Distributed Link Tracking Server                                        svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    TrkWks                             Distributed Link Tracking Client                                        svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    Tssdis                             Terminal Services Session Directory                                     tssdis.exe            5.2.3790.3959    Own Process          Stopped               LocalSystem
    UMWdf                              Windows User Mode Driver Framework                                      wdfmgr.exe            5.2.3790.3959    Own Process          Stopped               NT AUTHORITY\LocalService
    upnphost                           Universal Plug and Play Device Host                                     svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\LocalService
    UPS                                Uninterruptible Power Supply                                            ups.exe               5.2.3790.0       Own Process          Stopped               LocalSystem
    uTorrent                           uTorrent                                                                srvany.exe                             Own Process          Running               .\Administrator
    vds                                Virtual Disk Service                                                    vds.exe               5.2.3790.3959    Own Process          Running               LocalSystem
    VSS                                Volume Shadow Copy                                                      vssvc.exe             5.2.3790.3959    Own Process          Running               LocalSystem
    W32Time                            Windows Time                                                            svchost.exe           5.2.3790.3959    Share Process        Running               NT AUTHORITY\LocalService
    W3SVC                              World Wide Web Publishing Service                                       svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    WebClient                          WebClient                                                               svchost.exe           5.2.3790.3959    Share Process        Stopped               NT AUTHORITY\LocalService
    WHSArchiver                        Windows Home Server Archiver                                            whsarch.exe           6.0.1500.6       Own Process          Running               LocalSystem
    WHSBackup                          Windows Home Server Computer Backup                                     whsbackup.exe         6.0.1500.8       Own Process          Running               LocalSystem
    WHSTransportService                Windows Home Server Transport Service                                   TransportService.exe  6.0.1500.6       Own Process          Running               LocalSystem
    WinHttpAutoProxySvc                WinHTTP Web Proxy Auto-Discovery Service                                svchost.exe           5.2.3790.3959    Share Process        Stopped               NT AUTHORITY\LocalService
    winmgmt                            Windows Management Instrumentation                                      svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    WMConnectCDS                       Windows Media Connect Service                                           wmccds.exe            6.0.1500.6       Own Process          Stopped               NT AUTHORITY\NetworkService
    WmdmPmSN                           Portable Media Serial Number Service                                    svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    Wmi                                Windows Management Instrumentation Driver Extensions                    svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem
    WmiApSrv                           WMI Performance Adapter                                                 wmiapsrv.exe          5.2.3790.3959    Own Process          Stopped               LocalSystem
    wuauserv                           Automatic Updates                                                       svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    WZCSVC                             Wireless Configuration                                                  svchost.exe           5.2.3790.3959    Share Process        Running               LocalSystem
    xmlprov                            Network Provisioning Service                                            svchost.exe           5.2.3790.3959    Share Process        Stopped               LocalSystem


--------[ AX Files ]----------------------------------------------------------------------------------------------------

    acelpdec.ax                1.4.0.0                     ACELP.net Audio Decoder
    g711codc.ax                5.2.3790.3959               Intel G711 CODEC
    l3codecx.ax                1.5.0.50                    MPEG Layer-3 Audio Decoder
    mpeg2data.ax               6.5.3790.3959               Microsoft MPEG-2 Section and Table Acquisition Module
    mpg2splt.ax                6.5.3790.3959               DirectShow MPEG-2 Splitter.
    mpg4ds32.ax                8.0.0.4487                  Microsoft MPEG-4 Video Decompressor
    msadds32.ax                8.0.0.4487                  Windows Media Audio Decoder
    msscds32.ax                8.0.0.4487                  Microsoft Screen Video Decompressor
    vbisurf.ax                 5.3.3790.3959               VBI Surface Allocator Filter
    wiasf.ax                   1.0.0.0                     WIA Stream Snapshot Filter
    wmv8ds32.ax                8.0.0.4000                  Windows Media Video Decoder V8
    wmvds32.ax                 8.0.0.4487                  Windows Media Video Decoder


--------[ DLL Files ]---------------------------------------------------------------------------------------------------

    6to4svc.dll                5.2.3790.3959               Service that offers IPv6 connectivity over an IPv4 network.
    aaaamon.dll                5.2.3790.3959               Aaaa Monitor DLL
    acctres.dll                6.0.3790.0                  Microsoft Internet Account Manager Resources
    acledit.dll                5.2.3790.3959               Access Control List Editor
    aclui.dll                  5.2.3790.3959               Security Descriptor Editor
    activeds.dll               5.2.3790.3959               ADs Router Layer DLL
    actxprxy.dll               6.0.3790.3959               ActiveX Interface Marshaling Library
    admparse.dll               6.0.3790.3959               IEAK Global Policy Template Parser
    admwprox.dll               6.0.3790.3959               IIS Admin Com API Proxy dll
    adprop.dll                 5.2.3790.3959               Windows Active Directory Admin Property Pages
    adptif.dll                 5.2.3790.3959               IPX Interface via WinSock
    adsldp.dll                 5.2.3790.3959               ADs LDAP Provider DLL
    adsldpc.dll                5.2.3790.3959               ADs LDAP Provider C DLL
    adsmsext.dll               5.2.3790.3959               ADs LDAP Provider DLL
    adsnds.dll                 5.2.3790.3959               ADs NDS Provider DLL
    adsnt.dll                  5.2.3790.3959               ADs Windows NT Provider DLL
    adsnw.dll                  5.2.3790.3959               ADs Netware 3.12 Provider DLL
    advapi32.dll               5.2.3790.3959               Advanced Windows 32 Base API
    advpack.dll                6.0.3790.3959               ADVPACK
    aelupsvc.dll               5.2.3790.3959               Application Experience Lookup Service
    alrsvc.dll                 5.2.3790.3959               Alerter Service DLL
    amstream.dll               6.5.3790.3959               DirectShow Runtime.
    antiwpa.dll                3.4.6.0                     AntiWPA3 for X86
    antiwpa.dll_3fa3acf        3.4.6.0                     AntiWPA3 for X86
    apcups.dll                 5.2.3790.3959               APC Smart Provider
    apphelp.dll                5.2.3790.3959               Application Compatibility Client Library
    appmgmts.dll               5.2.3790.3959               Software installation Service
    appmgr.dll                 5.2.3790.3959               Software Installation Snapin Extenstion
    asferror.dll               10.0.0.3997                 ASF Error Definitions
    aspperf.dll                6.0.3790.3959               Active Server Pages Performance Monitor DLL
    asycfilt.dll               5.2.3790.3959               
    ati2cqag.dll               6.14.10.330                 Central Memory Manager / Queue Server Module
    ati2dvag.dll               6.14.10.6666                ATI Radeon WindowsNT Display Driver
    ati2edxx.dll               6.14.10.2510                ati2edxx
    ati2evxx.dll               6.14.10.4158                ATI External Event Utility DLL Module
    ati3duag.dll               6.14.10.471                 ati3duag.dll
    atiddc.dll                 6.14.10.8                   atiddc
    atidemgx.dll               2.0.2589.27141              Graphics DEM
    atiiiexx.dll               6.14.10.4004                .INF file installer
    atikvmag.dll               6.14.10.50                  Virtual Command And Memory Manager
    atioglxx.dll               6.14.10.6347                ATI OpenGL driver
    atipdlxx.dll               6.14.10.2515                ATI Desktop CWDDEDI DLL
    atitvo32.dll               6.14.10.4200                ATI RageTheater/ImpacTV2 COM interface 
    ativcoxx.dll               6.13.10.5                   32-bit ATI VCO Driver
    ativvaxx.dll               6.14.10.139                 Radeon Video Acceleration Universal Driver
    atkctrs.dll                5.2.3790.0                  Windows NT AppleTalk Perfmon Counter dll
    atl.dll                    3.5.2283.0                  ATL Module for Windows XP (Unicode)
    atmfd.dll                  5.1.2.226                   Windows NT OpenType/Type 1 Font Driver
    atmlib.dll                 5.1.2.226                   Windows NT OpenType/Type 1 API Library.
    atmpvcno.dll               5.2.3790.3959               Atm Epvc Install DLL
    atrace.dll                 5.2.3790.0                  Async Trace DLL
    audiodev.dll               5.2.3810.3997               Portable Media Devices Shell Extension
    audiosrv.dll               5.2.3790.3959               Windows Audio Service
    authz.dll                  5.2.3790.3959               Authorization Framework
    autodisc.dll               5.2.3790.0                  Windows AutoDiscovery API
    avicap.dll                 1.15.0.1                    AVI Capture DLL
    avicap32.dll               5.2.3790.3959               AVI Capture window class
    avifil32.dll               5.2.3790.3959               Microsoft AVI File support library
    avifile.dll                4.90.0.3000                 Microsoft AVI File support library
    azroles.dll                5.2.3790.3959               azroles Module
    azroleui.dll               5.2.3790.3959               Authorization Manager
    basesrv.dll                5.2.3790.3959               Windows NT BASE API Server DLL
    batmeter.dll               6.0.3790.3959               Battery Meter Helper DLL
    batt.dll                   5.2.3790.3959               Battery Class Installer
    bidispl.dll                5.2.3790.0                  Bidispl DLL
    bitsprx2.dll               6.6.3790.3959               Background Intelligent Transfer Service Proxy
    bitsprx3.dll               6.6.3790.3959               Background Intelligent Transfer Service 2.0 Proxy
    blackbox.dll               10.0.0.3997                 BlackBox DLL
    bootvid.dll                5.2.3790.0                  VGA Boot Driver
    browselc.dll               6.0.3790.0                  Shell Browser UI Library
    browser.dll                5.2.3790.3959               Computer Browser Service DLL
    browseui.dll               6.0.3790.4210               Shell Browser UI Library
    browsewm.dll               6.0.3790.3959               BrowseWM Player
    btpagnt.dll                5.2.3790.0                  Microsoft BOOTP subagent
    c_g18030.dll               5.2.3790.3959               GB18030 DBCS-Unicode Conversion DLL
    c_is2022.dll               5.2.3790.3959               ISO-2022 Code Page Translation DLL
    c_iscii.dll                5.2.3790.3959               ISCII Code Page Translation DLL
    cabinet.dll                5.2.3790.3959               Microsoft Cabinet File API
    cabview.dll                6.0.3790.3959               Cabinet File Viewer Shell Extension
    camocx.dll                 5.2.3790.3959               WIA Camera View DLL
    capesnpn.dll               5.2.3790.3959               Microsoft Certificate Template Management Extension
    cards.dll                  5.2.3790.0                  Entertainment Pack Cardplaying Helper DLL
    catsrv.dll                 2001.12.4720.3959           COM+ Configuration Catalog Server
    catsrvps.dll               2001.12.4720.3959           COM+ Configuration Catalog Server Proxy/Stub
    catsrvut.dll               2001.12.4720.3959           COM+ Configuration Catalog Server Utilities
    ccfapi32.dll               5.2.3790.0                  License Certificate API
    ccfgnt.dll                 7.2.3790.0                  Internet Configuration Library
    cdfview.dll                6.0.3790.3959               Channel Definition File Viewer
    cdm.dll                    7.0.6000.381                Windows Update CDM Stub
    cdosys.dll                 6.5.6757.0                  Microsoft CDO for Windows Library
    certadm.dll                5.2.3790.3959               Microsoft Certificate Services Admin
    certcli.dll                5.2.3790.3959               Microsoft Certificate Services Client
    certmgr.dll                5.2.3790.3959               Certificates snap-in
    certmmc.dll                5.2.3790.3959               Microsoft Certificate Services Management Console
    certpdef.dll               5.2.3790.3959               Windows default
    certtmpl.dll               5.2.3790.3959               Certificate Templates
    certxds.dll                5.2.3790.3959               Windows default
    cewmdm.dll                 10.0.3790.3997              Windows CE WMDM Service Provider
    cfgbkend.dll               5.2.3790.3959               Configuration Backend Interface
    cfgmgr32.dll               5.2.3790.0                  Configuration Manager Forwarder DLL
    cfosspeed.dll              4.20.1389.0                 cFosSpeed Install DLL
    chsbrkr.dll                2.0.2022.0                  Microsoft Chinese_Simplified Word Breaker Component
    chtbrkr.dll                3.0.0.1507                  Microsoft Traditional Chinese Word Breaker
    ciadmin.dll                5.2.3790.3959               CI Administration (MMC)
    cic.dll                    5.2.3790.3959               CIC - MMC controls for Taskpad
    ciodm.dll                  5.2.3790.3959               Indexing Service Admin Automation Objects
    clb.dll                    5.2.3790.0                  Column List Box
    clbcatex.dll               2001.12.4720.3959           COM+
    clbcatq.dll                2001.12.4720.3959           COM+ Configuration Catalog
    cliconfg.dll               2000.86.3959.0              SQL Client Configuration Utility DLL
    clusapi.dll                5.2.3790.3959               Cluster API Library
    clussprt.dll               5.2.3790.0                  Cluster Support API Library
    cmcfg32.dll                7.2.3790.3959               Microsoft Connection Manager Configuration Dll
    cmdial32.dll               7.2.3790.3959               Microsoft Connection Manager
    cmpbk32.dll                7.2.3790.0                  Microsoft Connection Manager Phonebook
    cmprops.dll                5.2.3790.3959               WMI Snapins
    cmsetacl.dll               5.2.3790.3959               Connection Manager ACL update
    cmutil.dll                 7.2.3790.3959               Microsoft Connection Manager Utility Lib
    cnbjmon.dll                0.3.0.0                     Langage Monitor for Canon Bubble-Jet Printer
    cnetcfg.dll                7.2.3790.0                  Connection Manager Library
    cnvfat.dll                 5.2.3790.3959               FAT File System Conversion Utility DLL
    colbact.dll                2001.12.4720.3959           COM+
    comaddin.dll               2001.12.4720.3959           COM+
    comcat.dll                 5.2.3790.0                  Microsoft Component Category Manager Library
    comctl32.dll               5.82.3790.3959              Common Controls Library
    comdlg32.dll               6.0.3790.3959               Common Dialogs DLL
    commdlg.dll                3.10.0.103                  Common Dialogs libraries
    compatui.dll               5.2.3790.3959               Application Compatibility UI Library
    compobj.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    compstui.dll               5.2.3790.0                  Common Property Sheet User Interface DLL
    comrepl.dll                2001.12.4720.3959           COM+
    comres.dll                 2001.12.4720.3959           COM+ Resources
    comsnap.dll                2001.12.4720.3959           COM+ Explorer MMC Snapin
    comsvcs.dll                2001.12.4720.3959           COM+ Services
    comuid.dll                 2001.12.4720.3959           COM+ Explorer UI
    confmsp.dll                5.2.3790.3959               Microsoft IP Conferencing Media Service Provider
    console.dll                5.2.3790.3959               Control Panel Console Applet
    convmsg.dll                5.2.3790.0                  CONVERT MESSAGES
    corpol.dll                 2003.2.3790.3959            Microsoft COM Runtime Execution Engine
    credui.dll                 5.2.3790.3959               Credential Manager User Interface
    crtdll.dll                 4.0.1183.1                  Microsoft C Runtime Library
    crypt32.dll                5.131.3790.3959             Crypto API32
    cryptdlg.dll               5.2.3790.0                  Microsoft Common Certificate Dialogs
    cryptdll.dll               5.2.3790.3959               Cryptography Manager
    cryptext.dll               5.131.3790.3959             Crypto Shell Extensions
    cryptnet.dll               5.131.3790.3959             Crypto Network Related API
    cryptsvc.dll               5.2.3790.3959               Cryptographic Services
    cryptui.dll                5.131.3790.3959             Microsoft Trust UI Provider
    cscdll.dll                 5.2.3790.3959               Offline Network Agent
    cscui.dll                  5.2.3790.3959               Client Side Caching UI
    csrsrv.dll                 5.2.3790.3959               Client Server Runtime Process
    csseqchk.dll               10.0.0.1009                 CSSeqChk
    ctl3d32.dll                2.31.0.0                    Ctl3D 3D Windows Controls
    ctl3dv2.dll                2.99.0.0                    Ctl3D 3D Windows NT(WOW) Controls
    d3d8.dll                   5.3.3790.3959               Microsoft Direct3D
    d3d8thk.dll                5.2.3790.0                  Microsoft Direct3D OS Thunk Layer
    d3d9.dll                   5.3.3790.3959               Microsoft Direct3D
    d3dim.dll                  5.2.3790.3959               Microsoft Direct3D
    d3dim700.dll               5.3.3790.3959               Microsoft Direct3D
    d3dpmesh.dll               5.2.3790.0                  Direct3D Progressive Mesh DLL
    d3dramp.dll                5.2.3790.0                  Microsoft Direct3D
    d3drm.dll                  5.2.3790.0                  Direct3D Retained Mode DLL
    d3dxof.dll                 5.2.3790.0                  DirectX Files DLL
    danim.dll                  6.3.1.148                   DirectX Media -- DirectAnimation
    dataclen.dll               6.0.3790.3959               Disk Space Cleaner for Windows
    datime.dll                 6.3.1.148                   TIME
    davclnt.dll                5.2.3790.3959               Web DAV Client DLL
    dbgeng.dll                 5.2.3790.3959               Windows Symbolic Debugger Engine
    dbghelp.dll                5.2.3790.3959               Windows Image Helper
    dbmsrpcn.dll               2000.86.3959.0              ConnectTo RPC Net Library
    dbnetlib.dll               2000.86.3959.0              Winsock Oriented Net DLL for SQL Clients
    dbnmpntw.dll               2000.86.3959.0              Named Pipes Net DLL for SQL Clients
    dciman32.dll               5.2.3790.0                  DCI Manager
    dcpromo.dll                5.2.3790.3959               Active Directory Installation Wizard
    ddeml.dll                  3.50.0.103                  DDE Management library
    ddraw.dll                  5.3.3790.3959               Microsoft DirectDraw
    ddrawex.dll                5.3.3790.3959               Direct Draw Ex
    deskadp.dll                6.0.3790.0                  Advanced display adapter properties
    deskmon.dll                6.0.3790.0                  Advanced display monitor properties
    deskperf.dll               5.2.3790.3959               Advanced display performance properties
    devenum.dll                6.5.3790.3959               Device enumeration.
    devmgr.dll                 5.2.3790.3959               Device Manager MMC Snapin
    dfrgifps.dll               5.2.3790.0                  Microsoft Defrag Interface proxy/stub
    dfrgres.dll                5.2.3790.0                  Disk Defragmenter Resource Module
    dfrgsnap.dll               5.2.3790.3959               Disk Defragmenter Snap-in Module
    dfrgui.dll                 5.2.3790.3959               Disk Defragmenter UI Module
    dfscore.dll                5.2.3790.3959               Distributed File System
    dfsgui.dll                 5.2.3790.3959               Distributed File System
    dfshim.dll                 2.0.50727.42                Application Deployment Support Library
    dfssetup.dll               5.2.3790.0                  Dfs setup extension
    dfsshlex.dll               5.2.3790.3959               Distributed File System shell extension
    dgnet.dll                  1.0.0.1                     Dgnet Module
    dgrpsetu.dll               2.4.53.0                    Digi RealPort Upgrade
    dgsetup.dll                4.0.23.0                    Digi AccelePort FEP5 ClassInstaller
    dhcpcsvc.dll               5.2.3790.3959               DHCP Client Service
    dhcpmon.dll                5.2.3790.3959               DHCP Monitor Dll
    dhcpsapi.dll               5.2.3790.3959               DHCP Server API Stub DLL
    diactfrm.dll               5.3.3790.3959               Microsoft DirectInput Mapper Framework
    digest.dll                 6.0.3790.3959               Digest SSPI Authentication Package
    dimap.dll                  5.2.3790.0                  Microsoft DirectInput Mapper
    dimsntfy.dll               5.2.3790.3959               DIMS Notification Handler
    dimsroam.dll               5.2.3790.3959               Key Roaming DIMS Provider DLL
    dinput.dll                 5.3.3790.3959               Microsoft DirectInput
    dinput8.dll                5.3.3790.3959               Microsoft DirectInput
    directdb.dll               6.0.3790.3959               Microsoft Direct Database API
    diskcopy.dll               6.0.3790.3959               Windows DiskCopy
    dispex.dll                 5.6.0.8832                  Microsoft (r) DispEx
    dmconfig.dll               5.2.3790.3959               Logical Disk Manager Configuration Library
    dmdlgs.dll                 5.2.3790.3959               Disk Management Snap-in Dialogs
    dmdskmgr.dll               5.2.3790.3959               Disk Management Snap-in Support Library
    dmdskres.dll               5.2.3790.0                  Disk Management Snap-in Resources
    dmintf.dll                 5.2.3790.0                  Disk Management DCOM Interface Stub
    dmivcitf.dll               5.2.3790.3959               Disk Management Snap-in Support Library
    dmocx.dll                  5.2.3790.0                  TreeView OCX
    dmserver.dll               5.2.3790.3959               Logical Disk Manager Service
    dmutil.dll                 5.2.3790.3959               Logical Disk Manager Utility Library
    dmvdsitf.dll               5.2.3790.3959               Disk Management Snap-in Support Library
    dnsapi.dll                 5.2.3790.3959               DNS Client API DLL
    dnsrslvr.dll               5.2.3790.3959               DNS Caching Resolver Service
    docprop.dll                5.2.3790.0                  OLE DocFile Property Page
    docprop2.dll               5.2.3790.3959               Microsoft DocProp Shell Ext
    domadmin.dll               5.2.3790.3959               Active Directory Domains and Trusts Snapin
    dpcdll.dll                 5.2.3790.3959               Dpcdll Module
    dplayx.dll                 5.3.3790.3959               Microsoft DirectPlay
    dpmodemx.dll               5.3.3790.3959               Modem and Serial Connection For DirectPlay
    dpnaddr.dll                5.3.3790.3959               Microsoft DirectPlay8 Address
    dpnet.dll                  5.3.3790.3959               Microsoft DirectPlay
    dpnhpast.dll               5.3.3790.3959               Microsoft DirectPlay NAT Helper PAST
    dpnhupnp.dll               5.3.3790.3959               Microsoft DirectPlay NAT Helper UPnP
    dpnlobby.dll               5.3.3790.3959               Microsoft DirectPlay8 Lobby
    dpvacm.dll                 5.3.3790.3959               Microsoft DirectPlay Voice ACM Provider
    dpvoice.dll                5.3.3790.3959               Microsoft DirectPlay Voice
    dpvvox.dll                 5.3.3790.3959               Microsoft DirectPlay Voice Voxware Provider
    dpwsockx.dll               5.3.3790.3959               Internet TCP/IP and IPX Connection For DirectPlay
    drmclien.dll               10.0.0.3997                 DRM Client DLL
    drmstor.dll                10.0.0.3997                 DRM Store DLL
    drmv2clt.dll               10.0.0.3997                 DRMv2 Client DLL
    drprov.dll                 5.2.3790.3959               Microsoft Terminal Server Network Provider
    ds16gt.dll                 3.510.3711.0                Microsoft ODBC Driver Setup Generic Thunk
    ds32gt.dll                 3.526.3959.0                Microsoft Data Access - ODBC Driver Setup Generic Thunk
    dsadmin.dll                5.2.3790.3959               Microsoft Directory Service Manager Snap-in
    dsauth.dll                 5.2.3790.3959               DS Authorization for Services
    dsdmo.dll                  5.3.3790.3959               DirectSound Effects
    dsdmoprp.dll               5.3.3790.3959               DirectSound Effects Property Pages
    dskquota.dll               5.2.3790.3959               Windows Shell Disk Quota Support DLL
    dskquoui.dll               5.2.3790.3959               Windows Shell Disk Quota UI DLL
    dsound.dll                 5.3.3790.3959               DirectSound
    dsound3d.dll               5.3.3790.3959               DirectSound3D LUT
    dsprop.dll                 5.2.3790.3959               Windows Active Directory Property Pages
    dsquery.dll                5.2.3790.3959               Directory Service Find
    dsrestor.dll               5.2.3790.3959               SBS 5.1 Setup Object
    dsrevt.dll                 5.2.3790.0                  DSREvents Module
    dssec.dll                  5.2.3790.3959               Directory Service Security UI
    dssenh.dll                 5.2.3790.3959               Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
    dsuiext.dll                5.2.3790.3959               Directory Service Common UI
    dsuiwiz.dll                5.2.3790.3959               Delegation of Control Wizard
    duser.dll                  5.2.3790.3959               Windows DirectUser Engine
    dx7vb.dll                  5.3.3790.3959               Microsoft DirectX for Visual Basic
    dx8vb.dll                  5.3.3790.3959               Microsoft DirectX for Visual Basic
    dxdiagn.dll                5.3.3790.3959               Microsoft DirectX Diagnostic Tool
    dxmasf.dll                 6.4.9.1125                  Windows Media Source Filter
    dxtmsft.dll                6.3.3790.4210               DirectX Media -- Image DirectX Transforms
    dxtrans.dll                6.3.3790.4210               DirectX Media -- DirectX Transform Core
    efsadu.dll                 5.2.3790.0                  File Encryption Utility
    els.dll                    5.2.3790.3959               Event Viewer Snapin
    encapi.dll                 5.3.3790.3959               Encoder API
    eqnclass.dll               5.0.21.62                   Equinox Multiport Serial Coinstaller
    ersvc.dll                  5.2.3790.3959               Windows Error Reporting Service
    es.dll                     2001.12.4720.3959           COM+
    esent.dll                  5.2.3790.3959               Server Database Storage Engine
    esent97.dll                6.0.3940.13                 Microsoft(R) Windows NT(TM) Server Database Storage Engine
    esentprf.dll               5.2.3790.3959               Server Database Storage Performance Library
    eventcls.dll               5.2.3790.3959               Microsoft Volume Shadow Copy Service event class
    eventlog.dll               5.2.3790.3959               Event Logging Service
    expsrv.dll                 6.0.72.9589                 Visual Basic for Applications Runtime - Expression Service
    exstrace.dll               6.0.3790.3959               Async Trace DLL
    extmgr.dll                 6.0.3790.3959               Extensions Manager
    f3ahvoas.dll               5.2.3790.0                  JP Japanese Keyboard Layout for Fujitsu FMV oyayubi-shift keyboard
    faultrep.dll               5.2.3790.3959               Windows Error Reporting
    fde.dll                    5.2.3790.3959               Folder Redirection Snapin Extension
    fdeploy.dll                5.2.3790.3959               Folder Redirection Winlogon Extension
    feclient.dll               5.2.3790.3959               Windows NT File Encryption Client Interfaces
    filemgmt.dll               5.2.3790.3959               Services and Shared Folders
    fltlib.dll                 5.2.3790.3959               Filter Library
    fmifs.dll                  5.2.3790.3959               FM IFS Utility DLL
    fontext.dll                5.2.3790.3959               Windows Font Folder
    fontsub.dll                5.2.3790.3959               Font Subsetting DLL
    framebuf.dll               5.2.3790.0                  Framebuffer Display Driver
    ftlx041e.dll               5.2.3790.0                  Thai Wordbreaker
    ftsrch.dll                 4.0.0.4553                  Microsoft Full-Text Search
    fwcfg.dll                  5.2.3790.3959               Windows Firewall Configuration Helper
    gcdef.dll                  5.3.3790.3959               Game Controllers Default Sheets
    gdi32.dll                  5.2.3790.4033               GDI Client DLL
    getuname.dll               5.2.3790.0                  Unicode name Dll for UCE
    glmf32.dll                 5.2.3790.3959               OpenGL Metafiling DLL
    glu32.dll                  5.2.3790.3959               OpenGL Utility Library DLL
    gpedit.dll                 5.2.3790.3959               GPEdit
    gpkcsp.dll                 5.2.3790.3959               Gemplus Cryptographic Service Provider
    gpkrsrc.dll                5.2.3790.3959               Gemplus Cryptographic Service Provider Resources
    gptext.dll                 5.2.3790.3959               GPTExt
    h323msp.dll                5.2.3790.3959               Microsoft H.323 Media Service Provider
    hal.dll                    5.2.3790.3959               Hardware Abstraction Layer DLL
    hbaapi.dll                 5.2.3790.3959               HBA API data interface dll for HBA_API_Rev_2-18_2002MAR1.doc
    hccoin.dll                 5.2.3790.3959               USB Coinstaller
    hhsetup.dll                5.2.3790.3959               Microsoft HTML Help
    hid.dll                    5.2.3790.3959               Hid User Library
    hlink.dll                  5.2.3790.3959               Microsoft Office 2000 component
    hnetcfg.dll                5.2.3790.3959               Home Networking Configuration Manager
    hnetmon.dll                5.2.3790.3959               Home Networking Monitor DLL
    hotplug.dll                5.2.3790.0                  Safely Remove Hardware applet
    httpapi.dll                5.2.3790.3959               HTTP Protocol Stack API
    htui.dll                   5.2.3790.0                  Common halftone Color Adjustment Dialogs
    ias.dll                    5.2.3790.3959               Internet Authentication Service
    iasacct.dll                5.2.3790.3959               IAS Accounting Provider
    iasads.dll                 5.2.3790.3959               IAS Active Directory Data Store
    iashlpr.dll                5.2.3790.3959               IAS Surrogate Component
    iasmmc.dll                 5.2.3790.3959               IAS MMC Snapin
    iasnap.dll                 5.2.3790.3959               IAS NAP Provider
    iasperf.dll                5.2.3790.3959               IAS Performance Monitoring DLL
    iaspolcy.dll               5.2.3790.3959               IAS Pipeline
    iasrad.dll                 5.2.3790.3959               IAS RADIUS Protocol Component
    iasrecst.dll               5.2.3790.3959               IAS Jet Database Access
    iassam.dll                 5.2.3790.3959               IAS NT SAM Provider
    iassdo.dll                 5.2.3790.3959               IAS SDO Component
    iassvcs.dll                5.2.3790.3959               IAS Services Component
    icaapi.dll                 5.2.3790.3959               DLL Interface to TermDD Device Driver
    icfgnt5.dll                6.0.3790.0                  Internet Connection Wizard
    icm32.dll                  5.2.3790.3959               Microsoft Color Management Module (CMM)
    icmp.dll                   5.2.3790.0                  ICMP DLL
    icmui.dll                  5.2.3790.3959               Microsoft Color Matching System User Interface DLL
    icwdial.dll                6.0.3790.3959               Internet Connection Wizard Autodialer
    icwphbk.dll                6.0.3790.3959               Internet Connection Wizard
    idq.dll                    5.2.3790.3959               Indexing Service ISAPI Extension
    ieakeng.dll                6.0.3790.3959               Internet Explorer Administration Kit Engine Library
    ieaksie.dll                6.0.3790.3959               Internet Explorer Snap-in Extension to Group Policy
    ieakui.dll                 6.0.3790.0                  Microsoft IEAK Shared UI DLL
    iedkcs32.dll               16.0.3790.3959              Microsoft Internet Explorer Customization DLL
    ieencode.dll               2001.7.25.0                 Microsoft Character Encoder
    iepeers.dll                6.0.3790.3959               Internet Explorer Peer Objects
    iernonce.dll               6.0.3790.3959               Extended RunOnce processing with UI
    iesetup.dll                6.0.3790.3959               IOD Version Map
    ifmon.dll                  5.2.3790.3959               IF Monitor DLL
    ifsutil.dll                5.2.3790.3959               IFS Utility DLL
    igmpagnt.dll               5.2.3790.0                  Microsoft IGMP subagent
    igmpv2.dll                 5.2.3790.3959               IGMPV2
    iismap.dll                 6.0.3790.3959               Microsoft IIS client certificate mapper
    iismui.dll                 6.0.3790.3959               Utility
    iisrstap.dll               6.0.3790.3959               IIS Restart API Proxy dll
    iisrtl.dll                 6.0.3790.3959               IIS RunTime Library
    iissuba.dll                6.0.3790.0                  Microsoft IIS sub-authentication handler
    ils.dll                    5.2.3790.3959               User Location Services Component Module
    imagehlp.dll               5.2.3790.3959               Windows NT Image Helper
    imeshare.dll               9.3.7020.0                  Microsoft Office IME Shared property library.
    imgutil.dll                6.0.3790.3959               IE plugin image decoder support DLL
    imjp81k.dll                8.1.7103.0                  Microsoft IME
    imm32.dll                  5.2.3790.3959               Windows IMM32 API Client DLL
    inetcfg.dll                6.0.3790.3959               Internet Connection Wizard Library
    inetcomm.dll               6.0.3790.3959               Microsoft Internet Messaging API
    inetcplc.dll               6.0.3790.0                  Internet Control Panel
    inetmib1.dll               5.2.3790.3959               Microsoft MIB-II subagent
    inetpp.dll                 5.2.3790.3959               Internet Print Provider DLL
    inetppui.dll               5.2.3790.0                  Internet Print Client DLL
    inetres.dll                6.0.3790.3959               Microsoft Internet Messaging API Resources
    infoadmn.dll               6.0.3790.0                  Internet Info Server Admin Client API Stubs
    infoctrs.dll               6.0.3790.0                  Common Internet Information Service Performance Counters
    infosoft.dll               5.2.3790.0                  Wordbreaker and stemmer dll
    initpki.dll                5.131.3790.3959             Microsoft Trust Installation and Setup
    input.dll                  5.2.3790.3959               Text Input DLL
    inseng.dll                 6.0.3790.3959               Install engine
    iologmsg.dll               5.2.3790.0                  IO Logging DLL
    ipbootp.dll                5.2.3790.3959               IP BOOTP
    iphlpapi.dll               5.2.3790.3959               IP Helper API
    ipmontr.dll                5.2.3790.3959               IP Router Monitor DLL
    ipnathlp.dll               5.2.3790.3959               Microsoft NAT Helper Components
    ippromon.dll               5.2.3790.3959               IP Protocols Monitor DLL
    iprip2.dll                 5.2.3790.3959               IP RIP
    iprop.dll                  5.2.3790.3959               OLE PropertySet Implementation
    iprtprio.dll               5.2.3790.3959               IP Routing Protocol Priority DLL
    iprtrmgr.dll               5.2.3790.3959               IP Router Manager
    ipsecsnp.dll               5.2.3790.3959               IP Security Policy Management Snap-in
    ipsecsvc.dll               5.2.3790.3959               Windows IPSec SPD Server DLL
    ipsmsnap.dll               5.2.3790.3959               IP Security Monitor Snap-in
    ipsnap.dll                 5.2.3790.3959               IP Routing Management Snapin
    ipv6mon.dll                5.2.3790.3959               IPv6 Monitor DLL
    ipxsap.dll                 5.2.3790.3959               SAP Agent DLL
    irclass.dll                5.2.3790.3959               Infrared Class Coinstaller
    isign32.dll                6.0.3790.3959               Internet Signup
    ismip.dll                  5.2.3790.3959               Ism Online Transport
    ismsink.dll                5.2.3790.0                  SMTP Event Sink for Intersite Messaging service
    ismsmtp.dll                5.2.3790.3959               SMTP plug-in for Intersite Messaging service
    isrdbg32.dll               0.0.0.0                     ISR Debug 32-bit Engine
    itircl.dll                 5.2.3790.3959               Microsoft InfoTech IR Local DLL
    itss.dll                   5.2.3790.3959               Microsoft InfoTech Storage System Library
    iuengine.dll               5.7.3790.3959               Windows Update Control Engine
    ixsso.dll                  5.2.3790.3959               Indexing Service Server-side Object
    iyuv_32.dll                5.2.3790.3959               Intel Indeo(R) Video YUV Codec
    jet.dll                    5.2.3790.0                  JET Engine DLL
    jet500.dll                 5.2.3790.3959               JET Engine DLL
    jgaw400.dll                36.0.0.0                    JG Audio Interface DLL
    jgdw400.dll                106.0.0.0                   JG ART DLL
    jgmd400.dll                34.0.0.0                    JG MIDI Player DLL
    jgpl400.dll                54.0.0.0                    JG ART Player DLL
    jgsd400.dll                17.0.0.0                    JG ART DLL
    jgsh400.dll                23.0.0.0                    JG Slide Show Player DLL
    jobexec.dll                5.0.0.1                     Active Setup Job Executer
    jscript.dll                5.6.0.8834                  Microsoft (r) JScript
    jsproxy.dll                6.0.3790.3959               JScript Proxy Auto-Configuration
    kbd101.dll                 5.2.3790.0                  JP Japanese Keyboard Layout for 101
    kbd101a.dll                5.2.3790.0                  KO Hangeul Keyboard Layout for 101 (Type A)
    kbd101b.dll                5.2.3790.0                  KO Hangeul Keyboard Layout for 101(Type B)
    kbd101c.dll                5.2.3790.0                  KO Hangeul Keyboard Layout for 101(Type C)
    kbd103.dll                 5.2.3790.0                  KO Hangeul Keyboard Layout for 103
    kbd106.dll                 5.2.3790.0                  JP Japanese Keyboard Layout for 106
    kbd106n.dll                5.2.3790.0                  JP Japanese Keyboard Layout for 106
    kbda1.dll                  5.2.3790.0                  Arabic_English_101 Keyboard Layout
    kbda2.dll                  5.2.3790.0                  Arabic_2 Keyboard Layout
    kbda3.dll                  5.2.3790.0                  Arabic_French_102 Keyboard Layout
    kbdal.dll                  5.2.3790.0                  Albania Keyboard Layout
    kbdarme.dll                5.2.3790.0                  Eastern Armenian Keyboard Layout
    kbdarmw.dll                5.2.3790.0                  Western Armenian Keyboard Layout
    kbdax2.dll                 5.2.3790.0                  JP Japanese Keyboard Layout for AX2
    kbdaze.dll                 5.2.3790.0                  Azerbaijan_Cyrillic Keyboard Layout
    kbdazel.dll                5.2.3790.0                  Azeri-Latin Keyboard Layout
    kbdbe.dll                  5.2.3790.0                  Belgian Keyboard Layout
    kbdbene.dll                5.2.3790.0                  Belgian Dutch Keyboard Layout
    kbdbhc.dll                 5.2.3790.3959               Bosnian (Cyrillic) Keyboard Layout
    kbdblr.dll                 5.2.3790.0                  Belarusian Keyboard Layout
    kbdbr.dll                  5.2.3790.0                  Brazilian Keyboard Layout
    kbdbu.dll                  5.2.3790.0                  Bulgarian Keyboard Layout
    kbdca.dll                  5.2.3790.0                  Canadian Multilingual Keyboard Layout
    kbdcan.dll                 5.2.3790.0                  Canadian National Standard Keyboard Layout
    kbdcr.dll                  5.2.3790.0                  Croatian/Slovenian Keyboard Layout
    kbdcz.dll                  5.2.3790.0                  Czech Keyboard Layout
    kbdcz1.dll                 5.2.3790.0                  Czech_101 Keyboard Layout
    kbdcz2.dll                 5.2.3790.0                  Czech_Programmer's Keyboard Layout
    kbdda.dll                  5.2.3790.0                  Danish Keyboard Layout
    kbddiv1.dll                5.2.3790.0                  Divehi Phonetic Keyboard Layout
    kbddiv2.dll                5.2.3790.0                  Divehi Typewriter Keyboard Layout
    kbddv.dll                  5.2.3790.0                  Dvorak US English Keyboard Layout
    kbdes.dll                  5.2.3790.0                  Spanish Alernate Keyboard Layout
    kbdest.dll                 5.2.3790.0                  Estonia Keyboard Layout
    kbdfa.dll                  5.2.3790.0                  Farsi Keyboard Layout
    kbdfc.dll                  5.2.3790.0                  Canadian French Keyboard Layout
    kbdfi.dll                  5.2.3790.0                  Finnish Keyboard Layout
    kbdfi1.dll                 5.2.3790.3959               Finnish-Swedish with Sami Keyboard Layout
    kbdfo.dll                  5.2.3790.0                  Froese Keyboard Layout
    kbdfr.dll                  5.2.3790.0                  French Keyboard Layout
    kbdgae.dll                 5.2.3790.0                  Gaelic Keyboard Layout
    kbdgeo.dll                 5.2.3790.0                  Georgian Keyboard Layout
    kbdgkl.dll                 5.2.3790.0                  Greek_Latin Keyboard Layout
    kbdgr.dll                  5.2.3790.0                  German Keyboard Layout
    kbdgr1.dll                 5.2.3790.0                  German_IBM Keyboard Layout
    kbdhe.dll                  5.2.3790.0                  Greek Keyboard Layout
    kbdhe220.dll               5.2.3790.0                  Greek IBM 220 Keyboard Layout
    kbdhe319.dll               5.2.3790.0                  Greek IBM 319 Keyboard Layout
    kbdheb.dll                 5.2.3790.0                  KBDHEB Keyboard Layout
    kbdhela2.dll               5.2.3790.0                  Greek IBM 220 Latin Keyboard Layout
    kbdhela3.dll               5.2.3790.0                  Greek IBM 319 Latin Keyboard Layout
    kbdhept.dll                5.2.3790.0                  Greek_Polytonic Keyboard Layout
    kbdhu.dll                  5.2.3790.0                  Hungarian Keyboard Layout
    kbdhu1.dll                 5.2.3790.0                  Hungarian 101-key Keyboard Layout
    kbdibm02.dll               5.2.3790.0                  JP Japanese Keyboard Layout for IBM 5576-002/003
    kbdic.dll                  5.2.3790.0                  Icelandic Keyboard Layout
    kbdindev.dll               5.2.3790.0                  Devanagari Keyboard Layout
    kbdinguj.dll               5.2.3790.0                  Gujarati Keyboard Layout
    kbdinhin.dll               5.2.3790.0                  Hindi Keyboard Layout
    kbdinkan.dll               5.2.3790.0                  Kannada Keyboard Layout
    kbdinmar.dll               5.2.3790.0                  Marathi Keyboard Layout
    kbdinpun.dll               5.2.3790.0                  Punjabi/Gurmukhi Keyboard Layout
    kbdintam.dll               5.2.3790.0                  Tamil Keyboard Layout
    kbdintel.dll               5.2.3790.0                  Telugu Keyboard Layout
    kbdir.dll                  5.2.3790.0                  Irish Keyboard Layout
    kbdit.dll                  5.2.3790.0                  Italian Keyboard Layout
    kbdit142.dll               5.2.3790.0                  Italian 142 Keyboard Layout
    kbdiultn.dll               5.2.3790.3959               Inuktitut Latin Keyboard Layout
    kbdjpn.dll                 5.2.3790.3959               JP Japanese Keyboard Layout Stub driver
    kbdkaz.dll                 5.2.3790.0                  Kazak_Cyrillic Keyboard Layout
    kbdkor.dll                 5.2.3790.3959               KO Hangeul Keyboard Layout Stub driver
    kbdkyr.dll                 5.2.3790.0                  Kyrgyz Keyboard Layout
    kbdla.dll                  5.2.3790.0                  Latin-American Spanish Keyboard Layout
    kbdlk41a.dll               5.2.3790.0                  DEC LK411-AJ Keyboard Layout
    kbdlk41j.dll               5.2.3790.0                  DEC LK411-JJ Keyboard Layout
    kbdlt.dll                  5.2.3790.0                  Lithuania Keyboard Layout
    kbdlt1.dll                 5.2.3790.0                  Lithuanian Keyboard Layout
    kbdlv.dll                  5.2.3790.0                  Latvia Keyboard Layout
    kbdlv1.dll                 5.2.3790.0                  Latvia-QWERTY Keyboard Layout
    kbdmac.dll                 5.2.3790.0                  FYROMacedonian_Cyrillic Keyboard Layout
    kbdmaori.dll               5.2.3790.3959               Maori Keyboard Layout
    kbdmlt47.dll               5.2.3790.3959               Maltese 47-key Keyboard Layout
    kbdmlt48.dll               5.2.3790.3959               Maltese 48-key Keyboard Layout
    kbdmon.dll                 5.2.3790.0                  Mongolian Keyboard Layout
    kbdne.dll                  5.2.3790.0                  Dutch Keyboard Layout
    kbdnec.dll                 5.2.3790.0                  JP Japanese Keyboard Layout for (NEC PC-9800)
    kbdnec95.dll               5.2.3790.0                  JP Japanese Keyboard Layout for (NEC PC-9800 Windows 95)
    kbdnecat.dll               5.2.3790.0                  JP Japanese Keyboard Layout for (NEC PC-9800 on PC98-NX)
    kbdnecnt.dll               5.2.3790.0                  JP Japanese NEC PC-9800 Keyboard Layout
    kbdnepr.dll                5.2.3790.3959               Nepali Keyboard Layout
    kbdno.dll                  5.2.3790.0                  Norwegian Keyboard Layout
    kbdno1.dll                 5.2.3790.3959               Norwegian with Sami Keyboard Layout
    kbdpash.dll                5.2.3790.3959               Pashto (Afghanistan) Keyboard Layout
    kbdpl.dll                  5.2.3790.0                  Polish Keyboard Layout
    kbdpl1.dll                 5.2.3790.0                  Polish Programmer's Keyboard Layout
    kbdpo.dll                  5.2.3790.0                  Portuguese Keyboard Layout
    kbdro.dll                  5.2.3790.0                  Romanian Keyboard Layout
    kbdru.dll                  5.2.3790.0                  Russian Keyboard Layout
    kbdru1.dll                 5.2.3790.0                  Russia(Typewriter) Keyboard Layout
    kbdsf.dll                  5.2.3790.0                  Swiss French Keyboard Layout
    kbdsg.dll                  5.2.3790.0                  Swiss German Keyboard Layout
    kbdsl.dll                  5.2.3790.0                  Slovak Keyboard Layout
    kbdsl1.dll                 5.2.3790.0                  Slovak(QWERTY) Keyboard Layout
    kbdsmsfi.dll               5.2.3790.3959               Sami Extended Finland-Sweden Keyboard Layout
    kbdsmsno.dll               5.2.3790.3959               Sami Extended Norway Keyboard Layout
    kbdsp.dll                  5.2.3790.0                  Spanish Keyboard Layout
    kbdsw.dll                  5.2.3790.0                  Swedish Keyboard Layout
    kbdsyr1.dll                5.2.3790.0                  Syriac Standard Keyboard Layout
    kbdsyr2.dll                5.2.3790.0                  Syriac Phoenetic Keyboard Layout
    kbdtat.dll                 5.2.3790.0                  Tatar_Cyrillic Keyboard Layout
    kbdth0.dll                 5.2.3790.0                  Thai Kedmanee Keyboard Layout
    kbdth1.dll                 5.2.3790.0                  Thai Pattachote Keyboard Layout
    kbdth2.dll                 5.2.3790.0                  Thai Kedmanee (non-ShiftLock) Keyboard Layout
    kbdth3.dll                 5.2.3790.0                  Thai Pattachote (non-ShiftLock) Keyboard Layout
    kbdtuf.dll                 5.2.3790.0                  Turkish F Keyboard Layout
    kbdtuq.dll                 5.2.3790.0                  Turkish Q Keyboard Layout
    kbduk.dll                  5.2.3790.0                  United Kingdom Keyboard Layout
    kbdukx.dll                 5.2.3790.3959               United Kingdom Extended Keyboard Layout
    kbdur.dll                  5.2.3790.0                  Ukrainian Keyboard Layout
    kbdurdu.dll                5.2.3790.0                  Urdu Keyboard Layout
    kbdus.dll                  5.2.3790.0                  United States Keyboard Layout
    kbdusa.dll                 5.2.3790.0                  US IBM Arabic 238_L Keyboard Layout
    kbdusl.dll                 5.2.3790.0                  Dvorak Left-Hand US English Keyboard Layout
    kbdusr.dll                 5.2.3790.0                  Dvorak Right-Hand US English Keyboard Layout
    kbdusx.dll                 5.2.3790.0                  US Multinational Keyboard Layout
    kbduzb.dll                 5.2.3790.0                  Uzbek_Cyrillic Keyboard Layout
    kbdvntc.dll                5.2.3790.0                  Vietnamese Keyboard Layout
    kbdycc.dll                 5.2.3790.0                  Serbian_Cyrillic Keyboard Layout
    kbdycl.dll                 5.2.3790.0                  Serbian_Latin Keyboard Layout
    kd1394.dll                 5.2.3790.0                  Kernel Debugger IEEE 1394 HW Extension DLL
    kdcom.dll                  5.2.3790.0                  Kernel Debugger HW Extension DLL
    kdcsvc.dll                 5.2.3790.3959               KDC Service
    kerberos.dll               5.2.3790.3959               Kerberos Security Package
    kernel32.dll               5.2.3790.4062               Windows NT BASE API Client DLL
    keymgr.dll                 5.2.3790.3959               Stored User Names and Passwords
    korwbrkr.dll               6.0.1529.1                  Korean WordBreaker
    ksuser.dll                 5.3.3790.3959               User CSA Library
    langwrbk.dll               5.2.3790.0                  English wordbreaker
    laprxy.dll                 10.0.0.3997                 Windows Media Logagent Proxy
    licdll.dll                 5.2.3790.3959               Licdll Module
    licmgr10.dll               6.0.3790.0                  ActiveX License Manager
    licwmi.dll                 5.2.3790.3959               Windows Product Activation Configuration WMI provider
    linkinfo.dll               5.2.3790.3959               Windows Volume Tracking
    llsrpc.dll                 5.2.3790.0                  License Logging Service RPC Interface
    lmhsvc.dll                 5.2.3790.3959               TCPIP NetBios Transport Services DLL
    lmrt.dll                   6.3.1.148                   Liquid Motion Runtime Control
    loadperf.dll               5.2.3790.0                  Load & Unload Performance Counters
    localsec.dll               5.2.3790.3959               Local Users and Groups MMC Snapin
    localspl.dll               5.2.3790.3959               Local Spooler DLL
    localui.dll                5.2.3790.0                  Local Monitor UI DLL
    loghours.dll               5.2.3790.0                  Schedule Dialog
    lpk.dll                    5.2.3790.3959               Language Pack
    lprhelp.dll                5.2.3790.3959               LPR Print Monitor
    lprmonui.dll               5.2.3790.0                  LPR Print Monitor UI
    lrwizdll.dll               5.2.3790.3959               Terminal Server License Server Activation Wizard
    lsasrv.dll                 5.2.3790.4186               LSA Server DLL
    lz32.dll                   5.2.3790.0                  LZ Expand/Compress API DLL
    lzexpand.dll               3.10.0.103                  Windows file expansion library
    mag_hook.dll               5.2.3790.3959               Microsoft Magnifier hook library file
    mapi32.dll                 1.0.2536.0                  Extended MAPI 1.0 for Windows NT
    mapistub.dll               1.0.2536.0                  Extended MAPI 1.0 for Windows NT
    mcastmib.dll               5.2.3790.0                  Microsoft Multicast subagent
    mcd32.dll                  5.2.3790.3959               OpenGL MCD Client DLL
    mcdsrv32.dll               5.2.3790.0                  MCD Server
    mchgrcoi.dll               5.2.3790.0                  Medium Changer CoInstaller
    mciavi32.dll               5.2.3790.3959               Video For Windows MCI driver
    mcicda.dll                 5.2.3790.0                  MCI driver for cdaudio devices
    mciole16.dll               3.10.0.103                  MCIOLE16 - OLE Handler DLL for MCI Objects
    mciole32.dll               5.2.3790.0                  MCI OLE DLL
    mciqtz32.dll               6.5.3790.3959               DirectShow MCI Driver
    mciseq.dll                 5.2.3790.3959               MCI driver for MIDI sequencer
    mciwave.dll                5.2.3790.3959               MCI driver for waveform audio
    mdhcp.dll                  5.2.3790.3959               Microsoft MDHCP Client COM Interface
    mdminst.dll                5.2.3790.3959               Modem Class Installer
    mf3216.dll                 5.2.3790.4033               32-bit to 16-bit Metafile Conversion DLL
    mfc40.dll                  4.1.0.6140                  MFCDLL Shared Library - Retail Version
    mfc40u.dll                 4.1.0.6141                  MFCDLL Shared Library - Retail Version
    mfc42.dll                  6.6.8063.0                  MFCDLL Shared Library - Retail Version
    mfc42u.dll                 6.6.8063.0                  MFCDLL Shared Library - Retail Version
    mfcsubs.dll                2001.12.4720.3959           COM+
    mgmtapi.dll                5.2.3790.3959               Microsoft SNMP Manager API (uses WinSNMP)
    microsoft.managementconsole.dll  5.2.3790.3959               MMCFx
    midimap.dll                5.2.3790.3959               Microsoft MIDI Mapper
    miglibnt.dll               5.2.3790.3959               NT migration dll support
    mimefilt.dll               2006.0.5730.0               Microsoft (R) IMimeFilter Persistent Handler DLL
    mlang.dll                  6.0.3790.3959               Multi Language Support DLL
    mll_hp.dll                 5.2.3790.3959               HP Media Label Library
    mll_mtf.dll                5.2.3790.3959               MTF (Microsoft Tape Format) Media Label Library
    mll_qic.dll                5.2.3790.3959               QIC113 Media Label Library
    mmcbase.dll                5.2.3790.3959               MMC Base DLL
    mmcex.dll                  5.2.3790.3959               MMCEx
    mmcfxcommon.dll            5.2.3790.3959               MMCFxCommon
    mmcndmgr.dll               5.2.3790.3959               MMC Node Manager DLL
    mmcshext.dll               5.2.3790.3959               MMC Shell Extension DLL
    mmfutil.dll                5.2.3790.3959               WMI Snapin Helpers
    mmsystem.dll               3.10.0.103                  System APIs for Multimedia
    mmutilse.dll               6.3.1.146                   Microsoft Multimedia Controls Utilities
    mnmdd.dll                  5.2.3790.3959               Application Sharing Display Driver
    mobsync.dll                5.2.3790.3959               Microsoft Synchronization Manager
    modemui.dll                5.2.3790.3959               Windows Modem Properties
    modex.dll                  5.2.3790.3959               ModeX Display Driver
    moricons.dll               5.2.3790.0                  Windows NT Setup Icon Resources Library
    mp43dmod.dll               10.0.0.3997                 Windows Media MPEG-4 Video Decoder
    mp4sdmod.dll               10.0.0.3997                 Corona Windows Media MPEG-4 S Video Decoder
    mpg4dmod.dll               10.0.0.3997                 Corona Windows Media MPEG-4 Video Decoder
    mpr.dll                    5.2.3790.3959               Multiple Provider Router DLL
    mprapi.dll                 5.2.3790.3959               Windows NT MP Router Administration DLL
    mprddm.dll                 5.2.3790.3959               Demand Dial Manager Supervisor
    mprdim.dll                 5.2.3790.3959               Dynamic Interface Manager
    mprmsg.dll                 5.2.3790.0                  Multi-Protocol Router Service Messages DLL
    mprsnap.dll                5.2.3790.3959               Routing and Remote Access Snapin
    mprui.dll                  5.2.3790.0                  Multiple Provider
    mqad.dll                   5.2.2003.3959               Message Queuing Active Directory Client
    mqads.dll                  5.2.2003.3959               Message Queuing Active Directory Service Provider
    mqcertui.dll               5.2.2003.3959               Message Queuing Certificate Dialogs
    mqdbodbc.dll               5.2.2003.3959               Message Queuing ODBC interface
    mqdscli.dll                5.2.2003.3959               Message Queuing Directory Service Client
    mqdssrv.dll                5.2.2003.3959               Message Queuing Directory Service Interface
    mqgentr.dll                5.2.2003.3959               Message Queuing Trigger Generic Object
    mqise.dll                  5.2.2003.3959               Message Queuing ISAPI Extension
    mqlogmgr.dll               2001.12.4720.3959           MS DTClog manager DLL
    mqmigrat.dll               5.2.2003.3959               Message Queuing 2.0 Migration
    mqoa.dll                   5.2.2003.3959               Message Queuing ActiveX Interface
    mqperf.dll                 5.2.2003.3959               Message Queuing Performance Coutners
    mqqm.dll                   5.2.2003.3959               Message Queuing Manager
    mqrt.dll                   5.2.2003.3959               Message Queuing Runtime
    mqrtdep.dll                5.2.2003.3959               Message Queuing Dependent Client
    mqsec.dll                  5.2.2003.3959               Message Queuing Utilities
    mqsnap.dll                 5.2.2003.3959               Message Queuing Snapin
    mqtrig.dll                 5.2.2003.3959               Message Queuing Trigger Object Module
    mqupgrd.dll                5.2.2003.3959               Message Queuing Setup Helper
    mqutil.dll                 5.2.2003.3959               Message Queuing Resource DLL
    msaatext.dll               2.0.10413.0                 Active Accessibility text support
    msacm.dll                  3.50.0.9                    Microsoft Audio Compression Manager
    msacm32.dll                5.2.3790.3959               Microsoft ACM Audio Filter
    msadce.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Cursor Engine
    msadcer.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Cursor Engine Resources
    msadcf.dll                 2.82.3959.0                 Microsoft Data Access - Remote Data Services Data Factory
    msadcfr.dll                2.82.3959.0                 Microsoft Data Access - Remote Data Services Data Factory Resources
    msadco.dll                 2.82.3959.0                 Microsoft Data Access - Remote Data Services Data Control
    msadcor.dll                2.82.3959.0                 Microsoft Data Access - Remote Data Services Data Control Resources
    msadcs.dll                 2.82.3959.0                 Microsoft Data Access - Remote Data Services ISAPI Library
    msadds.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Data Shape Provider
    msaddsr.dll                2.82.3959.0                 Microsoft Data Access -  OLE DB Data Shape Provider Resources
    msader15.dll               2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects Resources
    msado15.dll                2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects
    msadomd.dll                2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects (Multi-Dimensional)
    msador15.dll               2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects
    msadox.dll                 2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects Extensions
    msadrh15.dll               2.82.3959.0                 Microsoft Data Access - ActiveX Data Objects Rowset Helper
    msafd.dll                  5.2.3790.0                  Microsoft Windows Sockets 2.0 Service Provider
    msapsspc.dll               6.0.0.7755                  DPA Client for 32 bit platforms
    msasn1.dll                 5.2.3790.3959               ASN.1 Runtime APIs
    msaudite.dll               5.2.3790.3959               Security Audit Events DLL
    mscat32.dll                5.131.3790.0                MSCAT32 Forwarder DLL
    msclus.dll                 5.2.3790.3959               Microsoft Clustering Service Automation Interfaces.
    mscms.dll                  5.2.3790.3959               Microsoft Color Matching System DLL
    msconf.dll                 5.2.3790.3959               Conferencing Utility Dll
    mscoree.dll                2.0.50727.832               Microsoft .NET Runtime Execution Engine
    mscorier.dll               2.0.50727.42                Microsoft .NET Runtime IE resources
    mscories.dll               2.0.50727.42                Microsoft .NET IE SECURITY REGISTRATION
    mscpx32r.dll               3.526.3959.0                Microsoft Data Access - ODBC Code Page Translator Resources
    mscpxl32.dll               3.526.3959.0                Microsoft Data Access - ODBC Code Page Translator
    msctf.dll                  5.2.3790.3959               MSCTF Server DLL
    msctfp.dll                 5.2.3790.3959               MSCTFP Server DLL
    msdadc.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Data Conversion Stub
    msdadiag.dll               2.82.3959.0                 Microsoft Data Access - Built-In Diagnostics
    msdaenum.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Root Enumerator Stub
    msdaer.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Error Collection Stub
    msdaora.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Provider for Oracle
    msdaorar.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Provider for Oracle Resources
    msdaosp.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Simple Provider
    msdaprsr.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Persistence Services Resources
    msdaprst.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Persistence Services
    msdaps.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Interface Proxies/Stubs
    msdarem.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Remote Provider
    msdaremr.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Remote Provider Resources
    msdart.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Runtime Routines
    msdasc.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Service Components Stub
    msdasql.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Provider for ODBC Drivers
    msdasqlr.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Provider for ODBC Drivers Resources
    msdatl3.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Implementation Support Routines
    msdatt.dll                 2.82.3959.0                 Microsoft Data Access - OLE DB Temporary Table Services
    msdaurl.dll                9.2.3959.0                  Microsoft Data Access - OLE DB RootBinder Stub
    msdfmap.dll                2.82.3959.0                 Microsoft Data Access - Data Factory Handler
    msdmo.dll                  6.5.3790.3959               DMO Runtime
    msdtclog.dll               2001.12.4720.3959           MS DTClog manager DLL
    msdtcprx.dll               2001.12.4720.3959           MS DTCOLE Transactions interface proxy DLL
    msdtctm.dll                2001.12.4720.3959           MS DTCTransaction Manager DLL
    msdtcuiu.dll               2001.12.4720.3959           MS DTCadministrative component DLL
    msdxmlc.dll                6.4.9.1125                  Windows Media Player
    msencode.dll               2002.10.4.0                 Microsoft Character Encoder
    msexch40.dll               4.0.9502.0                  Microsoft Jet Exchange Isam
    msexcl40.dll               4.0.9502.0                  Microsoft Jet Excel Isam
    msftedit.dll               5.41.21.2506                Rich Text Edit Control, v4.1
    msgina.dll                 5.2.3790.3959               Windows NT Logon GINA DLL
    msgsvc.dll                 5.2.3790.3959               NT Messenger Service
    mshtml.dll                 6.0.3790.4210               Microsoft (R) HTML Viewer
    mshtmled.dll               6.0.3790.3959               Microsoft (R) HTML Editing Component
    mshtmler.dll               6.0.3790.3959               Microsoft (R) HTML Editing Component's Resource DLL
    msi.dll                    3.1.4000.4042               Windows Installer
    msident.dll                6.0.3790.3959               Microsoft Identity Manager
    msidle.dll                 6.0.3790.3959               User Idle Monitor
    msidntld.dll               6.0.3790.0                  Microsoft Identity Manager
    msieftp.dll                6.0.3790.3959               Microsoft Internet Explorer FTP Folder Shell Extension
    msihnd.dll                 3.1.4000.3959               Windows installer
    msimg32.dll                5.2.3790.0                  GDIEXT Client DLL
    msimsg.dll                 3.1.4000.3959               Windows Installer International Messages
    msimtf.dll                 5.2.3790.3959               Active IMM Server DLL
    msir3jp.dll                5.2.3790.3959               Japanese Wordbreaker and Stemmer
    msisip.dll                 3.1.4000.3959               MSI Signature SIP Provider
    msjet40.dll                4.0.9505.0                  Microsoft Jet Engine Library
    msjetoledb40.dll           4.0.9502.0                  Microsoft OLE DB Provider for Jet
    msjint40.dll               4.0.9502.0                  Microsoft Jet Database Engine International DLL
    msjro.dll                  2.82.3959.0                 Microsoft Jet and Replication Objects
    msjter40.dll               4.0.9502.0                  Microsoft Jet Database Engine Error DLL
    msjtes40.dll               4.0.9502.0                  Microsoft Jet Expression Service
    mslbui.dll                 5.2.3790.3959               LangageBar Add In
    msls31.dll                 3.10.349.0                  Microsoft Line Services library file
    msltus40.dll               4.0.9502.0                  Microsoft Jet Lotus 1-2-3 Isam
    msnetobj.dll               10.0.0.3997                 DRM ActiveX Network Object
    msnsspc.dll                6.1.1825.0                  MSN Internet Access
    msobjs.dll                 5.2.3790.0                  System object audit names
    msoeacct.dll               6.0.3790.3959               Microsoft Internet Account Manager
    msoert2.dll                6.0.3790.3959               Microsoft Outlook Express RT Lib
    msorc32r.dll               2.576.3959.0                Microsoft Data Access - ODBC Driver for Oracle Resources
    msorcl32.dll               2.576.3959.0                Microsoft Data Access - ODBC Driver for Oracle
    mspatcha.dll               5.2.3790.0                  Microsoft(R) Patch Engine
    mspbde40.dll               4.0.9502.0                  Microsoft Jet Paradox Isam
    mspmsnsv.dll               10.0.3790.3997              Microsoft Media Device Service Provider
    mspmsp.dll                 10.0.3790.3997              Microsoft Media Device Service Provider
    msports.dll                5.2.3790.3959               Ports Class Installer
    msppalrt.dll               5.2.3790.3959               Alert Library
    msppcntr.dll               5.2.3790.3959               Passport Manager Performance Counters
    mspplkrh.dll               5.2.3790.3959               LKR Hash Table Support
    msppmalr.dll               5.2.3790.3959               Passport Manager Alerts
    msppmd5.dll                5.2.3790.3959               ComMD5 Module
    msppmgr.dll                5.2.3790.3959               PassportManager
    msppnxus.dll               5.2.3790.3959               Nexus Support API
    msprivs.dll                5.2.3790.0                  Microsoft Privilege Translations
    msr2c.dll                  1.0.4211.0                  Microsoft Forms DLL
    msr2cenu.dll               1.0.4211.0                  Microsoft Forms DLL
    msratelc.dll               6.0.3790.0                  Internet Ratings and Local User Management DLL
    msrating.dll               6.0.3790.3959               Internet Ratings and Local User Management DLL
    msrclr40.dll               4.0.6508.0                  Microsoft Jet Briefcase Reconciler Library
    msrd2x40.dll               4.0.9502.0                  Microsoft (R) Red ISAM
    msrd3x40.dll               4.0.9502.0                  Microsoft (R) Red ISAM
    msrecr40.dll               4.0.6508.0                  Microsoft Jet Briefcase Reconciler Resource Library
    msrepl40.dll               4.0.9502.0                  Microsoft Replication Library
    msrle32.dll                5.2.3790.0                  Microsoft RLE Compressor
    mssap.dll                  10.0.0.3997                 DRM
    msscp.dll                  10.0.0.3997                 Windows Media Secure Content Provider
    mssign32.dll               5.131.3790.0                Microsoft Trust Signing APIs
    mssip32.dll                5.131.3790.0                MSSIP32 Forwarder DLL
    msswch.dll                 5.2.3790.0                  msswch
    mstask.dll                 5.2.3790.3959               Task Scheduler interface DLL
    mstext40.dll               4.0.9502.0                  Microsoft Jet Text Isam
    mstime.dll                 6.0.3790.4210               Microsoft (R) Timed Interactive Multimedia Extensions to HTML
    mstlsapi.dll               5.2.3790.3959               Microsoft Terminal Server Licensing
    mstscax.dll                5.2.3790.3959               Terminal Services ActiveX Client
    mstsmhst.dll               5.2.3790.3959               Terminal Services Connections multihost
    mstsmmc.dll                5.2.3790.3959               Remote Desktops Snap-in
    msutb.dll                  5.2.3790.3959               MSUTB Server DLL
    msv1_0.dll                 5.2.3790.3959               Microsoft Authentication Package v1.0
    msvbvm60.dll               6.0.97.82                   Visual Basic Virtual Machine
    msvcirt.dll                7.0.3790.0                  Windows NT IOStreams DLL
    msvcp50.dll                5.0.0.7051                  Microsoft (R) C++ Runtime Library
    msvcp60.dll                7.0.3790.3959               Windows NT C++ Runtime Library DLL
    msvcrt.dll                 7.0.3790.3959               Windows NT CRT DLL
    msvcrt20.dll               2.12.0.0                    Microsoft C Runtime Library
    msvcrt40.dll               5.2.3790.0                  VC 4.x CRT DLL (Forwarded to msvcrt.dll)
    msvfw32.dll                5.2.3790.3959               Microsoft Video for Windows DLL
    msvidc32.dll               5.2.3790.0                  Microsoft Video 1 Compressor
    msvidctl.dll               6.5.3790.3959               ActiveX control for streaming video
    msvideo.dll                1.15.0.1                    Microsoft Video for Windows DLL
    msw3prt.dll                5.2.3790.3959               ISAPI dll for Web Printing
    mswdat10.dll               4.0.9502.0                  Microsoft Jet Sort Tables
    mswebdvd.dll               6.5.3790.3959               MSWebDVD Module
    mswmdm.dll                 10.0.3790.3997              Windows Media Device Manager Core
    mswsock.dll                5.2.3790.3959               Microsoft Windows Sockets 2.0 Service Provider
    mswstr10.dll               4.0.9502.0                  Microsoft Jet Sort Library
    msxactps.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Transaction Proxies/Stubs
    msxbde40.dll               4.0.9502.0                  Microsoft Jet xBASE Isam
    msxml.dll                  8.0.7002.0                  XML OM for Win32
    msxml2.dll                 8.30.9528.0                 XML OM for Win32
    msxml2r.dll                8.1.7502.0                  XML Resources for Win32
    msxml3.dll                 8.90.1101.0                 MSXML 3.0 SP9
    msxml3r.dll                8.20.8730.1                 XML Resources
    msxmlr.dll                 8.0.6730.0                  XML Resources for Win32
    msyuv.dll                  5.2.3790.0                  Microsoft UYVY Video Decompressor
    mtxclu.dll                 2001.12.4720.3959           MS DTC amd MTS clustering support DLL
    mtxdm.dll                  2001.12.4720.3959           COM+
    mtxex.dll                  2001.12.4720.3959           COM+
    mtxlegih.dll               2001.12.4720.3959           COM+
    mtxoci.dll                 2001.12.4720.3959           Microsoft database support DLL for Oracle
    mycomput.dll               5.2.3790.3959               Computer Management
    mydocs.dll                 6.0.3790.3959               My Documents Folder UI
    napmmc.dll                 5.2.3790.3959               Remote Access Policy Snapin
    narrhook.dll               5.2.3790.0                  Microsoft Narrator Keyboard and WinEvent hook
    ncobjapi.dll               5.2.3790.3959               Microsoft Windows Operating System
    nddeapi.dll                5.2.3790.3959               Network DDE Share Management APIs
    nddenb32.dll               5.2.3790.3959               Network DDE NetBIOS Interface
    netapi.dll                 3.11.0.300                  Microsoft Network Dynamic Link Library for Microsoft Windows
    netapi32.dll               5.2.3790.3959               Net Win32 API DLL
    netcfgx.dll                5.2.3790.3959               Network Configuration Objects
    netevent.dll               5.2.3790.0                  Net Event Handler
    netfxperf.dll              1.1.4322.573                netfxperf.lib
    neth.dll                   5.2.3790.0                  Net Help Messages DLL
    netid.dll                  5.2.3790.3959               System Control Panel Applet; Network ID Page
    netlogon.dll               5.2.3790.3959               Net Logon Services DLL
    netman.dll                 5.2.3790.3959               Network Connections Manager
    netmsg.dll                 5.2.3790.0                  Net Messages DLL
    netplwiz.dll               5.2.3790.3959               Map Network Drives/Network Places Wizard
    netrap.dll                 5.2.3790.0                  Net Remote Admin Protocol DLL
    netshell.dll               5.2.3790.3959               Network Connections Shell
    netui0.dll                 5.2.3790.0                  NT LM UI Common Code - GUI Classes
    netui1.dll                 5.2.3790.0                  NT LM UI Common Code - Networking classes
    netui2.dll                 5.2.3790.3959               NT LM UI Common Code - GUI Classes
    newdev.dll                 5.2.3790.3959               Add Hardware Device Library
    nlhtml.dll                 2006.0.5730.0               HTML filter
    nmevtmsg.dll               5.2.3790.3959               NetMeeting Event Logging DLL
    nmmkcert.dll               5.2.3790.3959               NMMKCERT Library
    nntpapi.dll                6.0.3790.3959               NNTP Service Client API Stubs
    npptools.dll               5.2.3790.0                  NPP Tools Helper DLL
    nshipsec.dll               5.2.3790.3959               Net Shell IP Security helper DLL
    ntdll.dll                  5.2.3790.3959               NT Layer DLL
    ntdsa.dll                  5.2.3790.4070               NT5DS
    ntdsapi.dll                5.2.3790.3959               NT5DS
    ntdsatq.dll                5.2.3790.3959               Asynchronous Thread Queue
    ntdsbcli.dll               5.2.3790.3959               NT5DS
    ntdsbmsg.dll               5.2.3790.0                  NT5DS
    ntdsbsrv.dll               5.2.3790.3959               NT5DS
    ntdsetup.dll               5.2.3790.3959               NT5DS
    ntdskcc.dll                5.2.3790.3959               Windows NT Directory Service Knowledge Consistency Checker
    ntdsmsg.dll                5.2.3790.0                  NT5DS
    ntdsperf.dll               5.2.3790.3959               NT5DS
    ntfrsapi.dll               5.2.3790.3959               File Replication Service API DLL
    ntfrsprf.dll               5.2.3790.3959               NTFRSPRF
    ntfrsres.dll               5.2.3790.0                  Frs Event Handler
    ntlanman.dll               5.2.3790.3959               Microsoft Lan Manager
    ntlanui.dll                5.2.3790.0                  Lanman Control dll
    ntlanui2.dll               5.2.3790.0                  Network object shell UI
    ntlsapi.dll                5.2.3790.0                  Microsoft License Server Interface DLL
    ntmarta.dll                5.2.3790.3959               Windows NT MARTA provider
    ntmsapi.dll                5.2.3790.3959               Removable Storage Public Interfaces
    ntmsdba.dll                5.2.3790.3959               Removable Storage Database Interfaces
    ntmsevt.dll                5.2.3790.3959               Removable Storage Event Logger
    ntmsmgr.dll                5.2.3790.3959               Removable Storage Management
    ntmssvc.dll                5.2.3790.3959               Removable Storage Manager
    ntprint.dll                5.2.3790.3959               Spooler Setup DLL
    ntshrui.dll                6.0.3790.3959               Shell extensions for sharing
    ntvdmd.dll                 5.2.3790.0                  NTVDMD.DLL
    nwapi16.dll                5.2.3790.0                  NW Windows/Dos API DLL
    nwapi32.dll                5.2.3790.0                  NW Win32 API DLL
    nwcfg.dll                  5.2.3790.0                  NWC Configuration DLL
    nwevent.dll                5.2.3790.0                  Event Messages for Client Service for NetWare
    nwprovau.dll               5.2.3790.3959               Client Service for NetWare Provider and Authentication Package DLL
    nwwks.dll                  5.2.3790.3959               Client Service for Netware
    oakley.dll                 5.2.3790.3959               Oakley Key Manager
    objsel.dll                 5.2.3790.3959               Object Picker Dialog
    occache.dll                6.0.3790.3959               Object Control Viewer
    ocmanage.dll               5.2.3790.3959               Optional Component Manager Library
    odbc16gt.dll               3.510.3711.0                Microsoft ODBC Driver Generic Thunk
    odbc32.dll                 3.526.3959.0                Microsoft Data Access - ODBC Driver Manager
    odbc32gt.dll               3.526.3959.0                Microsoft Data Access - ODBC Driver Generic Thunk
    odbcbcp.dll                2000.86.3959.0              Microsoft BCP for ODBC
    odbcconf.dll               3.526.3959.0                Microsoft Data Access - ODBC Driver Configuration Program
    odbccp32.dll               3.526.3959.0                Microsoft Data Access - ODBC Installer
    odbccr32.dll               3.526.3959.0                Microsoft Data Access - ODBC Cursor Library
    odbccu32.dll               3.526.3959.0                Microsoft Data Access - ODBC Cursor Library
    odbcint.dll                3.526.3959.0                Microsoft Data Access - ODBC Resources
    odbcji32.dll               4.0.6305.0                  Microsoft ODBC Desktop Driver Pack 3.5
    odbcjt32.dll               4.0.6305.0                  Microsoft ODBC Desktop Driver Pack 3.5
    odbcp32r.dll               3.526.3959.0                Microsoft Data Access - ODBC Driver Manager Resources
    odbctrac.dll               3.526.3959.0                Microsoft Data Access - ODBC Driver Manager Trace
    oddbse32.dll               4.0.6305.0                  ODBC (3.0) driver for DBase
    odexl32.dll                4.0.6305.0                  ODBC (3.0) driver for Excel
    odfox32.dll                4.0.6305.0                  ODBC (3.0) driver for FoxPro
    odpdx32.dll                4.0.6305.0                  ODBC (3.0) driver for Paradox
    odtext32.dll               4.0.6305.0                  ODBC (3.0) driver for text files
    oemdspif.dll               6.14.1.20                   ATI Driver Interface DLL
    offfilt.dll                2006.0.5730.0               OffFilt
    ole2.dll                   2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    ole2disp.dll               2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole2nls.dll                2.10.3050.1                 OLE 2.1 16/32 Interoperability Library
    ole32.dll                  5.2.3790.3959               Microsoft OLE for Windows
    oleacc.dll                 4.2.5406.0                  Active Accessibility Core Component
    oleaccrc.dll               4.2.5406.0                  Active Accessibility Resource DLL
    oleaut32.dll               5.2.3790.4202               
    olecli.dll                 1.32.0.0                    Object Linking and Embedding Client Library
    olecli32.dll               5.2.3790.3959               Object Linking and Embedding Client Library
    olecnv32.dll               5.2.3790.3959               Microsoft OLE for Windows
    oledb32.dll                2.82.3959.0                 Microsoft Data Access - OLE DB Core Services
    oledb32r.dll               2.82.3959.0                 Microsoft Data Access - OLE DB Core Services Resources
    oledlg.dll                 5.2.3790.3959               Microsoft Windows(TM) OLE 2.0 User Interface Support
    oleprn.dll                 5.2.3790.3959               Oleprn DLL
    olepro32.dll               5.2.3790.3959               
    olesvr.dll                 1.11.0.0                    Object Linking and Embedding Server Library
    olesvr32.dll               5.2.3790.0                  Object Linking and Embedding Server Library
    olethk32.dll               5.2.3790.3959               Microsoft OLE for Windows
    opengl32.dll               5.2.3790.3959               OpenGL Client DLL
    ospf.dll                   5.2.3790.3959               IP OSPF
    ospfagnt.dll               5.2.3790.0                  Microsoft OSPF Subagent
    ospfmib.dll                5.2.3790.3959               IP OSPF MIB
    osuninst.dll               5.2.3790.0                  Uninstall Interface
    panmap.dll                 5.2.3790.0                  PANOSE(tm) Font Mapper
    pautoenr.dll               5.2.3790.3959               Auto Enrollment DLL
    pdh.dll                    5.2.3790.3959               Windows Performance Data Helper DLL
    perfctrs.dll               5.2.3790.3959               Performance Counters
    perfdisk.dll               5.2.3790.3959               Windows Disk Performance Objects DLL
    perfnet.dll                5.2.3790.3959               Windows Network Service Performance Objects DLL
    perfnw.dll                 5.2.3790.0                  Client Service for Netware Counters
    perfos.dll                 5.2.3790.3959               Windows System Performance Objects DLL
    perfproc.dll               5.2.3790.3959               Windows System Process Performance Objects DLL
    perfts.dll                 5.2.3790.3959               Windows Terminal Services Performance Objects
    photowiz.dll               5.2.3790.3959               Photo Printing Wizard
    pid.dll                    5.2.3790.0                  Microsoft PID
    pidgen.dll                 5.2.3790.3959               Pid3.0 generation
    pifmgr.dll                 5.2.3790.0                  Windows NT PIF Manager Icon Resources Library
    pjlmon.dll                 5.2.3790.3959               PJL Language monitor
    pkiview.dll                5.2.3790.0                  PKIView Dynamic Link Library
    pmspl.dll                  2.10.0.1                    Microsoft LAN Manager 2.1 Network Dynamic Link Library for Microsoft Windows
    pngfilt.dll                5.2.3790.3959               IE PNG plugin image decoder
    polstore.dll               5.2.3790.3959               Policy Storage dll
    powrprof.dll               6.0.3790.3959               Power Profile Helper DLL
    prflbmsg.dll               5.2.3790.0                  Perflib Event Messages
    printui.dll                5.2.3790.3959               Print UI DLL
    profmap.dll                5.2.3790.3959               Userenv
    psapi.dll                  5.2.3790.3959               Process Status Helper
    psbase.dll                 5.2.3790.3959               Protected Storage default provider
    pschdprf.dll               5.2.3790.3959               Microsoft Windows(TM) PSched Performance Monitor
    psnppagn.dll               5.2.3790.0                  DCOM Proxy for NPPAgent Object
    pstorec.dll                5.2.3790.3959               Protected Storage COM interfaces
    pstorsvc.dll               5.2.3790.3959               Protected storage server
    pwdfilter.dll              6.0.1500.6                  Home Server Password Filter
    pwdssp.dll                 5.2.3790.0                  Microsoft Clear Text Password Security Provider
    qasf.dll                   10.0.0.3997                 DirectShow ASF Support
    qcap.dll                   6.5.3790.3959               DirectShow Runtime.
    qdv.dll                    6.5.3790.3959               DirectShow Runtime.
    qdvd.dll                   6.5.3790.3959               DirectShow DVD PlayBack Runtime.
    qedit.dll                  6.5.3790.3959               DirectShow Editing.
    qedwipes.dll               6.5.3790.3959               DirectShow Editing SMPTE Wipes
    qmgr.dll                   6.6.3790.3959               Background Intelligent Transfer Service
    qmgrprxy.dll               6.6.3790.3959               Background Intelligent Transfer Service Proxy
    qosname.dll                5.2.3790.3959               Microsoft Windows GetQosByName Service Provider
    quartz.dll                 6.5.3790.4178               DirectShow Runtime.
    query.dll                  5.2.3790.3959               Content Index Utility DLL
    r2brand.dll                5.2.3790.3959               Windows Server R2 Branding Resources
    racpldlg.dll               5.2.3790.3959               Microsoft Remote Assistance
    rasadhlp.dll               5.2.3790.3959               Remote Access AutoDial Helper
    rasapi32.dll               5.2.3790.3959               Remote Access API
    rasauto.dll                5.2.3790.3959               Remote Access AutoDial Manager
    raschap.dll                5.2.3790.3959               Remote Access PPP CHAP
    rasctrs.dll                5.2.3790.3959               Windows NT Remote Access Perfmon Counter dll
    rasdlg.dll                 5.2.3790.3959               Remote Access Common Dialog API
    rasman.dll                 5.2.3790.3959               Remote Access Connection Manager
    rasmans.dll                5.2.3790.3959               Remote Access Connection Manager
    rasmontr.dll               5.2.3790.3959               RAS Monitor DLL
    rasmxs.dll                 5.2.3790.0                  Remote Access Device DLL for modems, PADs and switches
    rasppp.dll                 5.2.3790.3959               Remote Access PPP
    rasrad.dll                 5.2.3790.3959               Remote Access Service NT RADIUS client module
    rassapi.dll                5.2.3790.0                  Windows NT 4.0 Remote Access Administration DLL
    rasser.dll                 5.2.3790.0                  Remote Access Media DLL for COM ports
    rassfm.dll                 5.2.3790.3959               Remote Access Subauthentication dll
    rastapi.dll                5.2.3790.3959               Remote Access TAPI Compliance Layer
    rastls.dll                 5.2.3790.3959               Remote Access PPP EAP-TLS
    rasuser.dll                5.2.3790.3959               Dial-in User Management Snapin
    rcbdyctl.dll               5.2.3790.3959               Microsoft Remote Assistance
    rdchost.dll                5.2.3790.3959               RDSHost Client Module
    rdpcfgex.dll               5.2.3790.3959               Terminal Server Connection Configuration Extension for the RDP protocol
    rdpdd.dll                  5.2.3790.3959               RDP Display Driver
    rdpsnd.dll                 5.2.3790.0                  Terminal Server MultiMedia Driver
    rdpwsx.dll                 5.2.3790.3959               RDP Extension DLL
    regapi.dll                 5.2.3790.3959               Registry Configuration APIs
    regsvc.dll                 5.2.3790.3959               Remote Registry Service
    regwizc.dll                5.2.3790.3959               Online Registration Wizard
    remotepg.dll               5.2.3790.3959               Remote Sessions CPL Extension
    rend.dll                   5.2.3790.3959               Microsoft Rendezvous Control
    replprov.dll               5.2.3790.3959               ReplProv Module
    resutils.dll               5.2.3790.3959               Microsoft Cluster Resource Utility DLL
    riched20.dll               5.31.23.1225                Rich Text Edit Control, v3.1
    riched32.dll               5.2.3790.0                  Wrapper Dll for Richedit 1.0
    rigpsnap.dll               5.2.3790.3959               Remote Installation Service Policy Snap-in
    ripagnt.dll                5.2.3790.3959               Microsoft RIP2 subagent
    rnr20.dll                  5.2.3790.0                  Windows Socket2 NameSpace DLL
    routetab.dll               5.2.3790.0                  Microsoft Routing Table DLL
    rpcns4.dll                 5.2.3790.3959               Remote Procedure Call Name Service Client
    rpcnsh.dll                 5.2.3790.0                  RPC Netshell Helper
    rpcrt4.dll                 5.2.3790.4115               Remote Procedure Call Runtime
    rpcss.dll                  5.2.3790.3959               Distributed COM Services
    rrasprxy.dll               5.2.3790.0                  RRAS Config Proxy
    rsaenh.dll                 5.2.3790.3959               Microsoft Enhanced Cryptographic Provider
    rsfsaps.dll                5.2.3790.0                  FSA Proxy / Stub
    rshx32.dll                 5.2.3790.3959               Security Shell Extension
    rsmps.dll                  5.2.3790.0                  Removable Storage Proxy Stub
    rtm.dll                    5.2.3790.3959               Routing Table Manager
    rtrfiltr.dll               5.2.3790.3959               packet filters configuration
    rtrupg.dll                 5.2.3790.0                  Steelhead to NT 5.0 Registry Upgrader
    rtutils.dll                5.2.3790.3959               Routing Utilities
    rwnh.dll                   6.0.3790.3959               RWNH 
    sacsvr.dll                 5.2.3790.0                  Microsoft EMS SAC Service
    safrcdlg.dll               5.2.3790.0                  Microsoft PCHealth Remote Assistance File Open & Save controls
    safrdm.dll                 5.2.3790.3959               Microsoft Help Center Desktop Manager
    safrslv.dll                5.2.3790.3959               Microsoft Help Center Session Resolver
    samlib.dll                 5.2.3790.3959               SAM Library DLL
    samsrv.dll                 5.2.3790.3959               SAM Server DLL
    sbscrdll.dll               5.2.3790.3959               SBS Licensing
    sbscrevt.dll               5.2.3790.3959               DSREvents Module
    scarddlg.dll               5.2.3790.0                  SCardDlg - Smart Card Common Dialog
    sccbase.dll                5.2.3790.3959               Infineon SICRYPT Base Smart Card CSP
    sccsccp.dll                5.2.3790.3959               Infineon SICRYPT Smart Card Crypto Provider COM Objects
    scecli.dll                 5.2.3790.3959               Windows Security Configuration Editor Client Engine
    scesrv.dll                 5.2.3790.3959               Windows Security Configuration Editor Engine
    schannel.dll               5.2.3790.4068               TLS / SSL Security Provider
    schedsvc.dll               5.2.3790.3959               Task Scheduler Engine
    schmmgmt.dll               5.2.3790.3959               Active Directory Schema Manager MMC Snapin
    sclgntfy.dll               5.2.3790.0                  Secondary Logon Service Notification DLL
    scredir.dll                5.2.3790.3959               Smart Card Redirection for TS
    scripto.dll                6.5.6757.0                  Microsoft ScriptO
    scriptpw.dll               5.2.3790.0                  Scripting PassWord Utility
    scrobj.dll                 5.6.0.8832                  Windows (r) Script Component Runtime
    scrptutl.dll               5.2.3790.0                  Scripting Utils
    scrrun.dll                 5.6.0.8832                  Microsoft (r) Script Runtime
    sdpblb.dll                 5.2.3790.3959               Microsoft Sdpblb
    seclogon.dll               5.2.3790.3959               Secondary Logon Service DLL
    secoobe.dll                5.2.3790.3959               Security Out-of-the-box UI Helper
    secur32.dll                5.2.3790.3959               Security Support Provider Interface
    security.dll               5.2.3790.0                  Security Support Provider Interface
    sendcmsg.dll               5.2.3790.3959               Send Console Message
    sendmail.dll               6.0.3790.3959               Send Mail
    sens.dll                   5.2.3790.3959               System Event Notification Service (SENS)
    sensapi.dll                5.2.3790.3959               SENS Connectivity API DLL
    senscfg.dll                5.2.3790.0                  SENS Setup/Setup Tool
    serialui.dll               5.2.3790.3959               Serial Port Property Pages
    servdeps.dll               5.2.3790.3959               WMI Snapins
    serwvdrv.dll               5.2.3790.3959               Unimodem Serial Wave driver
    setupapi.dll               5.2.3790.3959               Windows Setup API
    sfc.dll                    5.2.3790.0                  Windows File Protection
    sfc_os.dll                 5.2.3790.3959               Windows File Protection
    sfcfiles.dll               5.2.3790.3959               Windows System File Checker
    sfmapi.dll                 5.2.3790.0                  Windows NT Macintosh File Service Client
    sfmatmsg.dll               5.2.3790.0                  Appletalk Messages DLL
    sfmctrs.dll                5.2.3790.0                  Windows NT Macintosh File Service Perfmon Counter dll
    sfmmon.dll                 5.2.3790.3959               AppleTalk Print Monitor
    sfmmsg.dll                 5.2.3790.0                  Afp Server Messages DLL
    sfmpsdib.dll               5.2.3790.3959               Windows NT Macintosh TrueImage Interpreter
    sfmpsfnt.dll               5.2.3790.3959               Windows NT Macintosh Font Manager
    sfmwshat.dll               5.2.3790.0                  Windows Sockets Helper DLL for AppleTalk
    shdoclc.dll                6.0.3790.0                  Shell Doc Object and Control Library
    shdocvw.dll                6.0.3790.4210               Shell Doc Object and Control Library
    shell.dll                  3.10.0.103                  Windows Shell library
    shell32.dll                6.0.3790.3959               Windows Shell Common Dll
    shellstyle.dll             5.2.3790.0                  Windows Shell Style Resource Dll
    shfolder.dll               6.0.3790.3959               Shell Folder Service
    shgina.dll                 6.0.3790.3959               Windows Shell User Logon
    shimeng.dll                5.2.3790.3959               Shim Engine DLL
    shimgvw.dll                6.0.3790.3959               Windows Picture and Fax Viewer
    shlwapi.dll                6.0.3790.3959               Shell Light-weight Utility Library
    shmedia.dll                6.0.3790.3959               Media File Property Extractor Shell Extension
    shscrap.dll                5.2.3790.3959               Shell scrap object handler
    shsvcs.dll                 6.0.3790.3959               Windows Shell Services Dll
    sigtab.dll                 5.2.3790.0                  File Integrity Settings
    sisbkup.dll                5.2.3790.3959               Single-Instance Store Backup Support Functions
    skdll.dll                  5.2.3790.0                  Serial Keys
    slayerxp.dll               6.0.5.0                     Compatibility Tab Shell Extension DLL
    slbcsp.dll                 5.2.3790.3959               Schlumberger Smart Card CryptoAPI Library
    slbiop.dll                 5.2.3790.3959               Schlumberger Smart Card Interoperability Library v2
    slbrccsp.dll               5.2.3790.3959               Schlumberger Smart Card CryptoAPI Resource File
    smlogcfg.dll               5.2.3790.3959               Performance Logs and Alerts Snap-in
    smtpapi.dll                6.0.3790.3959               SMTP Service Client API Stubs
    snapshot.dll               5.2.3790.3959               Windows State Snapshot
    snmpapi.dll                5.2.3790.3959               SNMP Utility Library
    snmpsnap.dll               5.2.3790.3959               SNMP snap-in
    softpub.dll                5.131.3790.0                Softpub Forwarder DLL
    spmsg.dll                  6.3.4.1                     Service Pack Messages
    spoolss.dll                5.2.3790.3959               Spooler SubSystem DLL
    spxcoins.dll               1.0.0.7                     Specialix MPS NT Upgrade CoInstaller
    sqloledb.dll               2000.86.3959.0              Microsoft OLE DB Provider for SQL Server
    sqlsrv32.dll               2000.86.3959.0              Microsoft SQL Server ODBC Driver
    sqlunirl.dll               2000.80.728.0               String Function .DLL for SQL Enterprise Components
    sqlwid.dll                 1999.10.20.0                Unicode Function .DLL for SQL Enterprise Components
    sqlwoa.dll                 1999.10.20.0                Unicode/ANSI Function .DLL for SQL Enterprise Components
    sqlxmlx.dll                2000.86.3959.0              Microsoft XML extensions for SQL Server
    srvsvc.dll                 5.2.3790.3959               Server Service DLL
    ssdpapi.dll                6.0.1500.6                  SSDP Client API DLL
    ssdpsrv.dll                6.0.1500.6                  SSDP Service DLL
    staxmem.dll                6.0.3790.3959               Microsoft Exchange Server Memory Management DLL
    stclient.dll               2001.12.4720.3959           COM+ Configuration Catalog Client
    sti.dll                    5.2.3790.3959               Still Image Devices client DLL 
    sti_ci.dll                 5.2.3790.3959               Still Image Class Installer
    stobject.dll               5.2.3790.3959               Systray shell service object
    storage.dll                2.10.35.35                  OLE 2.1 16/32 Interoperability Library
    storprop.dll               5.2.3790.3959               Property Pages for Storage Devices
    streamci.dll               5.2.3790.3959               Streaming Device Class Installer
    strmdll.dll                4.1.0.3936                  Windows Media Services Streamer Dll
    strmfilt.dll               6.0.3790.3959               Stream Filter Library
    svcpack.dll                5.2.3790.3959               Windows Service Pack Setup
    swprv.dll                  5.2.3790.3959               Microsoft Volume Shadow Copy Service software provider
    sxs.dll                    5.2.3790.3959               Fusion 2.5
    synceng.dll                5.2.3790.3959               Windows Briefcase Engine
    syncui.dll                 5.2.3790.3959               Windows Briefcase
    sysinv.dll                 4.10.0.2016                 Windows System Inventory
    syssetup.dll               5.2.3790.3959               Windows NT System Setup
    t2embed.dll                5.2.3790.3959               Microsoft T2Embed Font Embedding
    tapi.dll                   3.10.0.103                  Microsoft Windows(TM) Telephony Server16
    tapi3.dll                  5.2.3790.3959               Microsoft TAPI3
    tapi32.dll                 5.2.3790.3959               Microsoft Windows(TM) Telephony API Client DLL
    tapiperf.dll               5.2.3790.0                  Microsoft Windows(TM) Telephony Performance Monitor
    tapisnap.dll               5.2.3790.3959               Telephony Management Snapin
    tapisrv.dll                5.2.3790.3959               Microsoft Windows(TM) Telephony Server
    tapiui.dll                 5.2.3790.0                  Microsoft Windows(TM) Telephony API UI DLL
    tcpmib.dll                 5.2.3790.3959               Standard TCP/IP Port Monitor Helper DLL
    tcpmon.dll                 5.2.3790.3959               Standard TCP/IP Port Monitor DLL
    tcpmonui.dll               5.2.3790.3959               Standard TCP/IP Port Monitor UI DLL
    termmgr.dll                5.2.3790.3959               Microsoft TAPI3 Terminal Manager
    termsrv.dll                5.2.3790.3959               Terminal Server Service
    thawbrkr.dll               5.2.3790.3959               Thai Word Breaker
    themeui.dll                6.0.3790.3959               Windows Theme API
    tlntsvrp.dll               5.2.3790.0                  Microsoft Telnet Server Proxy Stub
    toolhelp.dll               3.10.0.103                  Windows Debug/Tool helper library
    traffic.dll                5.2.3790.3959               Microsoft Traffic Control 1.0 DLL
    trksvr.dll                 5.2.3790.0                  Distributed Link Tracking Server
    trkwks.dll                 5.2.3790.3959               Distributed Link Tracking Client
    tsappcmp.dll               5.2.3790.3959               Terminal Services Application Compatibility DLL
    tsbyuv.dll                 5.2.3790.0                  Toshiba Video Codec
    tscc.dll                   5.2.3790.3959               Terminal Services Connection Configuration
    tscfgwmi.dll               5.2.3790.3959               Terminal Server Configuration WMI provider
    tsd32.dll                  1.3.3.7                     DSP Group TrueSpeech(TM) Audio Encoder & Decoder
    tsddd.dll                  5.2.3790.0                  Framebuffer Display Driver
    tsec.dll                   5.2.3790.0                  Microsoft Windows(TM) TAPI Administration DLL
    tssdjet.dll                5.2.3790.3959               Terminal Server Load Balancing Jet RPC interface
    tsuserex.dll               5.2.3790.3959               Terminal Services Local Users and Groups Extension
    twext.dll                  6.0.3790.3959               Previous Versions property page
    txflog.dll                 2001.12.4720.3959           COM+
    typelib.dll                2.10.3029.1                 OLE 2.1 16/32 Interoperability Library
    udhisapi.dll               6.0.1500.6                  UPnP Device Host ISAPI Extension
    ufat.dll                   5.2.3790.3959               FAT Utility DLL
    ulib.dll                   5.2.3790.3959               File Utilities Support DLL
    umandlg.dll                5.2.3790.3959               UManDlg DLL
    umdmxfrm.dll               5.2.3790.0                  Unimodem Tranform Module
    umpnpmgr.dll               5.2.3790.3959               User-mode Plug-and-Play Service
    uniime.dll                 5.2.3790.3959               Generic IME 5.0 version
    unimdmat.dll               5.2.3790.3959               Unimodem Service Provider AT Mini Driver
    uniplat.dll                5.2.3790.3959               Unimodem AT Mini Driver Platform Driver for Windows NT
    untfs.dll                  5.2.3790.3959               NTFS Utility DLL
    upnp.dll                   6.0.1500.6                  Universal Plug and Play API
    upnphost.dll               6.0.1500.6                  UPnP Device Host
    ureg.dll                   5.2.3790.0                  Registry Utility DLL
    url.dll                    6.0.3790.3959               Internet Shortcut Shell Extension DLL
    urlmon.dll                 6.0.3790.4210               OLE32 Extensions for Win32
    usbmon.dll                 5.2.3790.3959               Standard Dynamic Printing Port Monitor DLL
    usbui.dll                  5.2.3790.3959               USB UI Dll
    user32.dll                 5.2.3790.4033               Windows USER API Client DLL
    userenv.dll                5.2.3790.3959               Userenv
    usp10.dll                  1.422.3790.3959             Uniscribe Unicode script processor
    utildll.dll                5.2.3790.3959               WinStation utility support DLL
    uxtheme.dll                6.0.3790.3959               Microsoft UxTheme Library
    vbajet32.dll               6.0.1.9431                  Visual Basic for Applications Development Environment - Expression Service Loader
    vbscript.dll               5.6.0.8832                  Microsoft (r) VBScript
    vdmdbg.dll                 5.2.3790.0                  VDMDBG.DLL
    vdmredir.dll               5.2.3790.0                  Virtual Dos Machine Network Interface Library
    vds_ps.dll                 5.2.3790.3959               Microsoft Virtual Disk Service proxy/stub
    vdsbas.dll                 5.2.3790.3959               Virtual Disk Service Basic Provider
    vdsdyndr.dll               5.2.3790.3959               VDS Dynamic Volume Provider, Version 1.0
    vdsutil.dll                5.2.3790.3959               Virtual Disk Service Utility Library
    ver.dll                    3.10.0.103                  Version Checking and File Installation Libraries
    verifier.dll               5.2.3790.3959               Standard application verifier provider dll
    version.dll                5.2.3790.3959               Version Checking and File Installation Libraries
    vfpodbc.dll                1.0.2.0                     vfpodbc
    vga.dll                    5.2.3790.0                  VGA 16 Colour Display Driver
    vga256.dll                 5.2.3790.0                  256 Color VGA\SVGA Display Driver
    vga64k.dll                 5.2.3790.0                  32K/64K color VGA\SVGA Display Driver
    vss_ddu.dll                5.2.3790.0                  Microsoft Volume Shadow Copy Service Dynamic Disk Utility
    vss_ps.dll                 5.2.3790.3959               Microsoft Volume Shadow Copy Service proxy/stub
    vssapi.dll                 5.2.3790.3959               Microsoft Volume Shadow Copy Requestor/Writer Services API DLL
    vssddups.dll               5.2.3790.0                  Microsoft Volume Shadow Copy Service Dynamic Disk Utility proxy/stub
    vssui.dll                  5.2.3790.3959               VSS Admin
    vwipxspx.dll               5.2.3790.0                  Virtual Dos Machine IPX/SPX Interface Library
    w03a2409.dll               5.2.3790.4043               Service Pack Messages
    w03a3409.dll               5.2.3790.4210               Service Pack Messages
    w32time.dll                5.2.3790.3959               Windows Time Service
    w32topl.dll                5.2.3790.0                  Windows NT Topology Maintenance Tool
    w3ssl.dll                  6.0.3790.0                  SSL service for HTTP
    wab32.dll                  6.0.3790.3959               Microsoft (R) Address Book DLL
    wab32res.dll               6.0.3790.3959               Microsoft (R) Address Book DLL
    wamregps.dll               6.0.3790.0                  WAMREG Proxy Stub 
    wavemsp.dll                5.2.3790.3959               Microsoft Wave MSP
    wdfapi.dll                 5.2.3790.3959               Windows User Mode Driver Framework API
    wdigest.dll                5.2.3790.3959               Microsoft Digest Access
    webcheck.dll               6.0.3790.3959               Web Site Monitor
    webclnt.dll                5.2.3790.3959               Web DAV Service DLL
    webhits.dll                5.2.3790.0                  Indexing Service Webhits
    webvw.dll                  6.0.3790.3959               Shell WebView Content & Control Library
    whsbrand.dll               5.2.3790.4099               WHS Branding Resources
    wiadefui.dll               5.2.3790.3959               WIA Scanner Default UI
    wiadss.dll                 5.2.3790.3959               WIA TWAIN compatibility layer
    wiarpc.dll                 5.2.3790.3959               Windows Image Acquisition RPC client DLL
    wiascr.dll                 5.2.3790.3959               WIA Scripting Layer
    wiaservc.dll               5.2.3790.3959               Still Image Devices Service
    wiashext.dll               5.2.3790.3959               Imaging Devices Shell Folder UI
    wiavideo.dll               5.2.3790.3959               WIA Video
    wifeman.dll                3.10.0.103                  Windows WIFE interface core component
    win32spl.dll               5.2.3790.3959               32-bit Spooler API DLL
    win87em.dll                                            
    winbrand.dll               5.2.3790.0                  Windows Branding Resources
    winfax.dll                 5.2.3790.3959               Microsoft  Fax API Support DLL
    wininet.dll                6.0.3790.4210               Internet Extensions for Win32
    winipsec.dll               5.2.3790.3959               Windows IPSec SPD Client DLL
    winmm.dll                  5.2.3790.3959               MCI API DLL
    winnls.dll                 3.10.0.103                  Windows IME interface core component
    winntbbu.dll               5.2.3790.4099               Windows Setup BillBrd DLL
    winrnr.dll                 5.2.3790.3959               LDAP RnR Provider DLL
    winscard.dll               5.2.3790.3959               Microsoft Smart Card API
    winshfhc.dll               5.2.3790.3959               File Has Code parser
    winsmon.dll                5.2.3790.3959               WINS Monitor Dll
    winsock.dll                3.10.0.103                  Windows Socket 16-Bit DLL
    winsrpc.dll                5.2.3790.0                  WINS RPC LIBRARY
    winsrv.dll                 5.2.3790.4043               Windows Server DLL
    winsta.dll                 5.2.3790.3959               Winstation Library
    wintrust.dll               5.131.3790.3959             Microsoft Trust Verification APIs
    wkssvc.dll                 5.2.3790.3959               Workstation Service DLL
    wlanmon.dll                5.2.3790.3959               Wireless Monitor Snapin
    wlbsctrl.dll               5.2.3790.3959               Network Load Balancing API
    wldap32.dll                5.2.3790.3959               Win32 LDAP API DLL
    wlnotify.dll               5.2.3790.3959               Common DLL to receive Winlogon notifications
    wlsnp.dll                  5.2.3790.3959               Wireless Network Policy Management Snap-in
    wlstore.dll                5.2.3790.3959               Policy Storage dll
    wmadmod.dll                10.0.0.3997                 Windows Media Audio Decoder
    wmadmoe.dll                10.0.0.3997                 Windows Media Audio Encoder/Transcoder
    wmasf.dll                  10.0.0.4000                 Windows Media ASF DLL
    wmdmlog.dll                10.0.3790.3997              Windows Media Device Manager Logger
    wmdmps.dll                 10.0.3790.3997              Windows Media Device Manager Proxy Stub
    wmdrmdev.dll               10.0.0.3997                 Windows Media DRM for Network Devices Registration DLL
    wmdrmnet.dll               10.0.0.3997                 Windows Media DRM for Network Devices DLL
    wmerrenu.dll               8.0.0.4487                  Windows Media Services Error Definitions
    wmerror.dll                10.0.0.3997                 Windows Media Error Definitions (English)
    wmi.dll                    5.2.3790.0                  WMI DC and DP functionality
    wmidx.dll                  10.0.0.3997                 Windows Media Indexer DLL
    wmiprop.dll                5.2.3790.3959               WDM Provider Dynamic Property Page CoInstaller
    wmiscmgr.dll               5.0.1636.1                  WMI Filter Manager
    wmnetmgr.dll               10.0.0.3997                 Windows Media Network Plugin Manager DLL
    wmp.dll                    10.0.0.3998                 Windows Media Player Core
    wmpasf.dll                 10.0.0.3997                 Windows Media Filter Shim
    wmpcd.dll                  10.0.0.3997                 Windows Media Player
    wmpcore.dll                9.0.0.2991                  Windows Media Player
    wmpdxm.dll                 10.0.0.3997                 Windows Media 6.4 Player Shim
    wmpencen.dll               10.0.0.3997                 Windows Media Player Encoding Module
    wmploc.dll                 10.0.0.3997                 Windows Media Player
    wmpshell.dll               10.0.0.3997                 Windows Media Player Launcher
    wmpsrcwp.dll               10.0.0.3997                 WMPSrcWp Module
    wmpui.dll                  9.0.0.2991                  Windows Media Player
    wmsdmod.dll                10.0.0.3997                 Windows Media Screen Decoder
    wmsdmoe2.dll               10.0.0.3997                 Corona Windows Media Screen Encoder
    wmspdmod.dll               10.0.0.3997                 Windows Media Audio 9 Voice Decoder
    wmspdmoe.dll               10.0.0.3997                 Windows Media Audio 9 Voice Encoder
    wmvadvd.dll                10.0.0.3997                 Windows Media Video 9 Decoder
    wmvadve.dll                10.0.0.3997                 Windows Media Video 9 Decoder
    wmvcore.dll                10.0.0.3997                 Windows Media Playback/Authoring DLL
    wmvdmod.dll                10.0.0.3997                 Windows Media Video Decoder
    wmvdmoe2.dll               10.0.0.3997                 Windows Media Video Encoder
    wow32.dll                  5.2.3790.3959               32-bit WOW Subsystem Library
    wowfax.dll                 0.2.0.0                     Windows 3.1 Compatible Fax Driver DLL
    wowfaxui.dll               0.2.0.0                     Windows 3.1 Compatible Fax Driver UI DLL
    wpd_ci.dll                 5.2.3810.3997               Driver Setup Class Installer for Windows Portable Devices
    wpdsp.dll                  5.2.3810.3997               WMDM Service Provider for Windows Portable Devices
    ws03res.dll                5.2.3790.3959               Service Pack Messages
    ws2_32.dll                 5.2.3790.3959               Windows Socket 2.0 32-Bit DLL
    ws2help.dll                5.2.3790.3959               Windows Socket 2.0 Helper for Windows NT
    wsecedit.dll               5.2.3790.3959               Security Configuration UI Module
    wshatm.dll                 5.2.3790.0                  Windows Sockets Helper DLL
    wshcon.dll                 5.6.0.8832                  Microsoft (r) Windows Script Controller
    wshext.dll                 5.6.0.8832                  Microsoft (r) Shell Extension for Windows Script Host
    wship6.dll                 5.2.3790.3959               IPv6 Helper DLL
    wshisn.dll                 5.2.3790.0                  NWLINK2 Socket Helper DLL
    wshnetbs.dll               5.2.3790.0                  Netbios Windows Sockets Helper DLL
    wshqos.dll                 5.2.3790.3959               Windows QoS Helper DLL
    wshrm.dll                  5.2.3790.0                  Windows Sockets Helper DLL for PGM
    wshtcpip.dll               5.2.3790.3959               Windows Sockets Helper DLL
    wsnmp32.dll                5.2.3790.3959               Microsoft WinSNMP v2.0 Manager API
    wsock32.dll                5.2.3790.0                  Windows Socket 32-Bit DLL
    wstdecod.dll               5.3.3790.3959               WST Decoder Filter
    wtsapi32.dll               5.2.3790.3959               Windows Terminal Server SDK APIs
    wuapi.dll                  7.0.6000.381                Windows Update Client API
    wuaueng.dll                7.0.6000.381                Windows Update Agent
    wuaueng1.dll               5.7.3790.3959               Windows Update AutoUpdate Engine
    wuauserv.dll               5.7.3790.3959               Windows Update AutoUpdate Service
    wucltui.dll                7.0.6000.381                Windows Update Client UI Plugin
    wups.dll                   7.0.6000.381                Windows Update client proxy stub
    wups2.dll                  7.0.6000.381                Windows Update client proxy stub 2
    wuweb.dll                  7.0.6000.381                Windows Update Web Control
    wzcdlg.dll                 5.2.3790.3959               Wireless Zero Configuration Service UI
    wzcsapi.dll                5.2.3790.3959               Wireless Zero Configuration service API
    wzcsvc.dll                 5.2.3790.3959               Wireless Zero Configuration Service
    xactsrv.dll                5.2.3790.3959               Downlevel API Server DLL
    xenroll.dll                5.131.3686.0                XEnroll
    xmllite.dll                1.0.1018.0                  Microsoft XmlLite Library
    xmlprov.dll                5.2.3790.3959               Network Provisioning Service
    xmlprovi.dll               5.2.3790.3959               Network Provisioning Service Client API
    xolehlp.dll                2001.12.4720.3959           MS DTChelper APIs DLL
    xpob2res.dll               5.2.3790.3959               Service Pack 2 OOB Messages
    xpsp2res.dll               5.2.3790.3959               Service Pack 2 Messages
    zipfldr.dll                6.0.3790.3959               Compressed (zipped) Folders


--------[ UpTime ]------------------------------------------------------------------------------------------------------

    Current Session:
      Last Shutdown Time                                3/16/2008 15:39:19
      Last Boot Time                                    3/28/2008 17:43:17
      Current Time                                      3/29/2008 10:58:41
      UpTime                                            62152 sec (0 days, 17 hours, 15 min, 52 sec)

    UpTime Statistics:
      First Boot Time                                   1/15/2008 04:43:47
      First Shutdown Time                               1/15/2008 04:42:46
      Total UpTime                                      560871 sec (6 days, 11 hours, 47 min, 51 sec)
      Total DownTime                                    53889553 sec (623 days, 17 hours, 19 min, 13 sec)
      Longest UpTime                                    167340 sec (1 days, 22 hours, 29 min, 0 sec)
      Longest DownTime                                  2218538 sec (25 days, 16 hours, 15 min, 38 sec)
      Total Reboots                                     99
      System Availability                               1.03%

    Bluescreen Statistics:
      Total Bluescreens                                 0

    Information:
      Information                                       The above statistics are based on System Event Log entries


--------[ Share ]-------------------------------------------------------------------------------------------------------

    Downloads                       Folder        Fertige uTorrent Downloads                D:\shares\Downloads
    Music                           Folder        Shared folder for music                   D:\shares\Music
    Photos                          Folder        Shared folder for photos                  D:\shares\Photos
    Public                          Folder        Shared folder for miscellaneous files     D:\shares\Public
    Software                        Folder        Shared folder for software installation programs  D:\shares\Software
    Users                           Folder        Personal folders for users                D:\shares\Users
    Videos                          Folder        Shared folder for videos                  D:\shares\Videos
    ADMIN$                          Folder        Remote Admin                              C:\WINDOWS
    C$                              Folder        Default share                             C:\
    D$                              Folder        Default share                             D:\
    IPC$                            IPC           Remote IPC                                


--------[ Opened Files ]------------------------------------------------------------------------------------------------

    89857      CHRISTOPH WEBER       D:\shares\Software\Tools
    90328      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r41
    90378      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd1\xcite-youngsfa.r37
    90393      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd1\xcite-youngsfa.r12
    90402      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r10
    90414      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.rar
    90422      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r42
    90423      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Sample\xcite-youngsf-sample.avi
    90429      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r05
    90430      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd1\xcite-youngsfa.r22
    90434      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r02
    90435      ADMINISTRATOR         D:\shares\Downloads\Young.Slut.Fun.XXX.DVDrip.XviD-XCiTE\Cd2\xcite-youngsfb.r06


--------[ Account Security ]--------------------------------------------------------------------------------------------

    Account Security Properties:
      Computer Role                                     Primary
      Domain Name                                       WEBERSERVER
      Primary Domain Controller                         Not Specified
      Forced Logoff Time                                Disabled
      Min / Max Password Age                            0 / 49710 days
      Minimum Password Length                           0 chars
      Password History Length                           Disabled
      Lockout Threshold                                 50 attempts
      Lockout Duration                                  30 min
      Lockout Observation Window                        30 min


--------[ Logon ]-------------------------------------------------------------------------------------------------------

    Administrator                                 WEBERSERVER               WEBERSERVER
    Administrator                                 WEBERSERVER               WEBERSERVER
    WEBERSERVER$                                                            WORLDWIDEWEBER


--------[ Users ]-------------------------------------------------------------------------------------------------------

  [ Administrator ]

    User Properties:
      User Name                                         Administrator
      Full Name                                         Administrator
      Comment                                           Built-in account for administering the computer/domain
      Member Of Groups                                  Windows Home Server Users; Administrators
      Logon Count                                       215
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  No
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 Yes
      Read-Only Password                                No
      Password Never Expires                            Yes

  [ ASPNET ]

    User Properties:
      User Name                                         ASPNET
      Full Name                                         ASP.NET Machine Account
      Comment                                           Account used for running the ASP.NET worker process (aspnet_wp.exe)
      User Comment                                      Account used for running the ASP.NET worker process (aspnet_wp.exe)
      Member Of Groups                                  Users
      Logon Count                                       2
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  No
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 No
      Read-Only Password                                Yes
      Password Never Expires                            Yes

  [ Christoph Weber ]

    User Properties:
      User Name                                         Christoph Weber
      Full Name                                         Christoph Weber
      Member Of Groups                                  RW_3; RW_4; RW_5; RW_6; RW_7; RW_B; RW_G; Windows Home Server Users; Print Operators; Remote Desktop Users; Users
      Logon Count                                       2
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  No
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 Yes
      Read-Only Password                                No
      Password Never Expires                            Yes

  [ Guest ]

    User Properties:
      User Name                                         Guest
      Full Name                                         Guest
      Comment                                           Built-in account for guest access to the computer/domain
      Member Of Groups                                  Windows Home Server Users; Guests
      Logon Count                                       0
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  Yes
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 No
      Read-Only Password                                Yes
      Password Never Expires                            Yes

  [ IUSR_WEBERSERVER ]

    User Properties:
      User Name                                         IUSR_WEBERSERVER
      Full Name                                         Internet Guest Account
      Comment                                           Built-in account for anonymous access to Internet Information Services
      User Comment                                      Built-in account for anonymous access to Internet Information Services
      Member Of Groups                                  Guests
      Logon Count                                       55
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  No
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 No
      Read-Only Password                                Yes
      Password Never Expires                            Yes

  [ IWAM_WEBERSERVER ]

    User Properties:
      User Name                                         IWAM_WEBERSERVER
      Full Name                                         Launch IIS Process Account
      Comment                                           Built-in account for Internet Information Services to start out of process applications
      User Comment                                      Built-in account for Internet Information Services to start out of process applications
      Member Of Groups                                  IIS_WPG
      Logon Count                                       0
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  No
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 No
      Read-Only Password                                Yes
      Password Never Expires                            Yes

  [ SUPPORT_388945a0 ]

    User Properties:
      User Name                                         SUPPORT_388945a0
      Full Name                                         CN=Microsoft Corporation,L=Redmond,S=Washington,C=US
      Comment                                           This is a vendor's account for the Help and Support Service
      Member Of Groups                                  HelpServicesGroup
      Logon Count                                       0
      Disk Quota                                        -

    User Features:
      Logon Script Executed                             Yes
      Account Disabled                                  Yes
      Locked Out User                                   No
      Home Folder Required                              No
      Password Required                                 Yes
      Read-Only Password                                Yes
      Password Never Expires                            Yes


--------[ Local Groups ]------------------------------------------------------------------------------------------------

  [ Administrators ]

    Local Group Properties:
      Comment                                           Administrators have complete and unrestricted access to the computer/domain

    Group Members:
      Administrator                                     

  [ Backup Operators ]

    Local Group Properties:
      Comment                                           Backup Operators can override security restrictions for the sole purpose of backing up or restoring files

  [ Distributed COM Users ]

    Local Group Properties:
      Comment                                           Members are allowed to launch, activate and use Distributed COM objects on this machine.

  [ Guests ]

    Local Group Properties:
      Comment                                           Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted

    Group Members:
      Guest                                             
      IUSR_WEBERSERVER                                  Internet Guest Account

  [ HelpServicesGroup ]

    Local Group Properties:
      Comment                                           Group for the Help and Support Center

    Group Members:
      SUPPORT_388945a0                                  CN=Microsoft Corporation,L=Redmond,S=Washington,C=US

  [ IIS_WPG ]

    Local Group Properties:
      Comment                                           IIS Worker Process Group

    Group Members:
      IWAM_WEBERSERVER                                  Launch IIS Process Account
      NETWORK SERVICE                                   
      SERVICE                                           
      SYSTEM                                            

  [ Network Configuration Operators ]

    Local Group Properties:
      Comment                                           Members in this group can have some administrative privileges to manage configuration of networking features

  [ Performance Log Users ]

    Local Group Properties:
      Comment                                           Members of this group have remote access to schedule logging of performance counters on this computer

    Group Members:
      NETWORK SERVICE                                   

  [ Performance Monitor Users ]

    Local Group Properties:
      Comment                                           Members of this group have remote access to monitor this computer

  [ Power Users ]

    Local Group Properties:
      Comment                                           Power Users possess most administrative powers with some restrictions.  Thus, Power Users can run legacy applications in addition to certified applications

  [ Print Operators ]

    Local Group Properties:
      Comment                                           Members can administer domain printers

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ Remote Desktop Users ]

    Local Group Properties:
      Comment                                           Members in this group are granted the right to logon remotely

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ Replicator ]

    Local Group Properties:
      Comment                                           Supports file replication in a domain

  [ RO_3 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Photos

  [ RO_4 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Music

  [ RO_5 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Videos

  [ RO_6 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Software

  [ RO_7 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Public

  [ RO_B ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Christoph Weber

  [ RO_G ]

    Local Group Properties:
      Comment                                           Members of this group have ReadOnly access to share Downloads

  [ RW_3 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Photos

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_4 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Music

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_5 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Videos

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_6 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Software

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_7 ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Public

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_B ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Christoph Weber

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ RW_G ]

    Local Group Properties:
      Comment                                           Members of this group have ReadWrite access to share Downloads

    Group Members:
      Christoph Weber                                   Christoph Weber

  [ TelnetClients ]

    Local Group Properties:
      Comment                                           Members of this group have access to Telnet Server on this system.

  [ Users ]

    Local Group Properties:
      Comment                                           Users are prevented from making accidental or intentional system-wide changes.  Thus, Users can run certified applications, but not most legacy applications

    Group Members:
      ASPNET                                            ASP.NET Machine Account
      Authenticated Users                               
      Christoph Weber                                   Christoph Weber
      INTERACTIVE                                       

  [ Windows Home Server Users ]

    Local Group Properties:
      Comment                                           Members of this group can be managed by Windows Home Server

    Group Members:
      Administrator                                     
      Christoph Weber                                   Christoph Weber
      Guest                                             


--------[ Global Groups ]-----------------------------------------------------------------------------------------------

  [ None ]

    Global Group Properties:
      Comment                                           Ordinary users

    Group Members:
      Administrator                                     
      ASPNET                                            ASP.NET Machine Account
      Christoph Weber                                   Christoph Weber
      Guest                                             
      IUSR_WEBERSERVER                                  Internet Guest Account
      IWAM_WEBERSERVER                                  Launch IIS Process Account
      SUPPORT_388945a0                                  CN=Microsoft Corporation,L=Redmond,S=Washington,C=US


--------[ Fonts ]-------------------------------------------------------------------------------------------------------

    @Batang                                   Roman       Regular        Baltic                  16 x 32   40 %
    @Batang                                   Roman       Regular        Central European        16 x 32   40 %
    @Batang                                   Roman       Regular        Cyrillic                16 x 32   40 %
    @Batang                                   Roman       Regular        Greek                   16 x 32   40 %
    @Batang                                   Roman       Regular        Hangul                  16 x 32   40 %
    @Batang                                   Roman       Regular        Turkish                 16 x 32   40 %
    @Batang                                   Roman       Regular        Western                 16 x 32   40 %
    @BatangChe                                Modern      Regular        Baltic                  16 x 32   40 %
    @BatangChe                                Modern      Regular        Central European        16 x 32   40 %
    @BatangChe                                Modern      Regular        Cyrillic                16 x 32   40 %
    @BatangChe                                Modern      Regular        Greek                   16 x 32   40 %
    @BatangChe                                Modern      Regular        Hangul                  16 x 32   40 %
    @BatangChe                                Modern      Regular        Turkish                 16 x 32   40 %
    @BatangChe                                Modern      Regular        Western                 16 x 32   40 %
    @Dotum                                    Swiss       Regular        Baltic                  16 x 32   40 %
    @Dotum                                    Swiss       Regular        Central European        16 x 32   40 %
    @Dotum                                    Swiss       Regular        Cyrillic                16 x 32   40 %
    @Dotum                                    Swiss       Regular        Greek                   16 x 32   40 %
    @Dotum                                    Swiss       Regular        Hangul                  16 x 32   40 %
    @Dotum                                    Swiss       Regular        Turkish                 16 x 32   40 %
    @Dotum                                    Swiss       Regular        Western                 16 x 32   40 %
    @DotumChe                                 Modern      Regular        Baltic                  16 x 32   40 %
    @DotumChe                                 Modern      Regular        Central European        16 x 32   40 %
    @DotumChe                                 Modern      Regular        Cyrillic                16 x 32   40 %
    @DotumChe                                 Modern      Regular        Greek                   16 x 32   40 %
    @DotumChe                                 Modern      Regular        Hangul                  16 x 32   40 %
    @DotumChe                                 Modern      Regular        Turkish                 16 x 32   40 %
    @DotumChe                                 Modern      Regular        Western                 16 x 32   40 %
    @Gulim                                    Swiss       Regular        Baltic                  16 x 32   40 %
    @Gulim                                    Swiss       Regular        Central European        16 x 32   40 %
    @Gulim                                    Swiss       Regular        Cyrillic                16 x 32   40 %
    @Gulim                                    Swiss       Regular        Greek                   16 x 32   40 %
    @Gulim                                    Swiss       Regular        Hangul                  16 x 32   40 %
    @Gulim                                    Swiss       Regular        Turkish                 16 x 32   40 %
    @Gulim                                    Swiss       Regular        Western                 16 x 32   40 %
    @GulimChe                                 Modern      Regular        Baltic                  16 x 32   40 %
    @GulimChe                                 Modern      Regular        Central European        16 x 32   40 %
    @GulimChe                                 Modern      Regular        Cyrillic                16 x 32   40 %
    @GulimChe                                 Modern      Regular        Greek                   16 x 32   40 %
    @GulimChe                                 Modern      Regular        Hangul                  16 x 32   40 %
    @GulimChe                                 Modern      Regular        Turkish                 16 x 32   40 %
    @GulimChe                                 Modern      Regular        Western                 16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Baltic                  16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Central European        16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Cyrillic                16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Greek                   16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Hangul                  16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Turkish                 16 x 32   40 %
    @Gungsuh                                  Roman       Regular        Western                 16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Baltic                  16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Central European        16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Cyrillic                16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Greek                   16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Hangul                  16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Turkish                 16 x 32   40 %
    @GungsuhChe                               Modern      Regular        Western                 16 x 32   40 %
    @MingLiU                                  Modern      Regular        CHINESE_BIG5            16 x 32   40 %
    @MingLiU                                  Modern      Regular        Western                 16 x 32   40 %
    @MS Gothic                                Modern      Regular        Baltic                  16 x 32   40 %
    @MS Gothic                                Modern      Regular        Central European        16 x 32   40 %
    @MS Gothic                                Modern      Regular        Cyrillic                16 x 32   40 %
    @MS Gothic                                Modern      Regular        Greek                   16 x 32   40 %
    @MS Gothic                                Modern      Regular        Japanese                16 x 32   40 %
    @MS Gothic                                Modern      Regular        Turkish                 16 x 32   40 %
    @MS Gothic                                Modern      Regular        Western                 16 x 32   40 %
    @MS Mincho                                Modern      Regular        Baltic                  16 x 32   40 %
    @MS Mincho                                Modern      Regular        Central European        16 x 32   40 %
    @MS Mincho                                Modern      Regular        Cyrillic                16 x 32   40 %
    @MS Mincho                                Modern      Regular        Greek                   16 x 32   40 %
    @MS Mincho                                Modern      Regular        Japanese                16 x 32   40 %
    @MS Mincho                                Modern      Regular        Turkish                 16 x 32   40 %
    @MS Mincho                                Modern      Regular        Western                 16 x 32   40 %
    @MS PGothic                               Swiss       Regular        Baltic                  13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Central European        13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Cyrillic                13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Greek                   13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Japanese                13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Turkish                 13 x 32   40 %
    @MS PGothic                               Swiss       Regular        Western                 13 x 32   40 %
    @MS PMincho                               Roman       Regular        Baltic                  13 x 32   40 %
    @MS PMincho                               Roman       Regular        Central European        13 x 32   40 %
    @MS PMincho                               Roman       Regular        Cyrillic                13 x 32   40 %
    @MS PMincho                               Roman       Regular        Greek                   13 x 32   40 %
    @MS PMincho                               Roman       Regular        Japanese                13 x 32   40 %
    @MS PMincho                               Roman       Regular        Turkish                 13 x 32   40 %
    @MS PMincho                               Roman       Regular        Western                 13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Baltic                  13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Central European        13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Cyrillic                13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Greek                   13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Japanese                13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Turkish                 13 x 32   40 %
    @MS UI Gothic                             Swiss       Regular        Western                 13 x 32   40 %
    @NSimSun                                  Modern      Regular        CHINESE_GB2312          16 x 32   40 %
    @NSimSun                                  Modern      Regular        Western                 16 x 32   40 %
    @PMingLiU                                 Roman       Regular        CHINESE_BIG5            16 x 32   40 %
    @PMingLiU                                 Roman       Regular        Western                 16 x 32   40 %
    @SimHei                                   Special     Regular        CHINESE_GB2312          16 x 32   40 %
    @SimSun                                   Special     Regular        CHINESE_GB2312          16 x 32   40 %
    @SimSun                                   Special     Regular        Western                 16 x 32   40 %
    Aharoni                                   Special     Bold           Hebrew                  15 x 32   70 %
    Andalus                                   Special     Regular        Arabic                  13 x 49   40 %
    Angsana New                               Roman       Regular        Thai                     8 x 43   40 %
    Angsana New                               Roman       Regular        Western                  8 x 43   40 %
    AngsanaUPC                                Roman       Regular        Thai                     8 x 43   40 %
    Arabic Transparent                        Special     Regular        Arabic                  13 x 38   40 %
    Arial Black                               Swiss       Regular        Baltic                  18 x 45   40 %
    Arial Black                               Swiss       Regular        Central European        18 x 45   40 %
    Arial Black                               Swiss       Regular        Cyrillic                18 x 45   40 %
    Arial Black                               Swiss       Regular        Greek                   18 x 45   40 %
    Arial Black                               Swiss       Regular        Turkish                 18 x 45   40 %
    Arial Black                               Swiss       Regular        Western                 18 x 45   40 %
    Arial                                     Swiss       Regular        Arabic                  14 x 36   40 %
    Arial                                     Swiss       Regular        Baltic                  14 x 36   40 %
    Arial                                     Swiss       Regular        Central European        14 x 36   40 %
    Arial                                     Swiss       Regular        Cyrillic                14 x 36   40 %
    Arial                                     Swiss       Regular        Greek                   14 x 36   40 %
    Arial                                     Swiss       Regular        Hebrew                  14 x 36   40 %
    Arial                                     Swiss       Regular        Turkish                 14 x 36   40 %
    Arial                                     Swiss       Regular        Vietnamese              14 x 36   40 %
    Arial                                     Swiss       Regular        Western                 14 x 36   40 %
    Batang                                    Roman       Regular        Baltic                  16 x 32   40 %
    Batang                                    Roman       Regular        Central European        16 x 32   40 %
    Batang                                    Roman       Regular        Cyrillic                16 x 32   40 %
    Batang                                    Roman       Regular        Greek                   16 x 32   40 %
    Batang                                    Roman       Regular        Hangul                  16 x 32   40 %
    Batang                                    Roman       Regular        Turkish                 16 x 32   40 %
    Batang                                    Roman       Regular        Western                 16 x 32   40 %
    BatangChe                                 Modern      Regular        Baltic                  16 x 32   40 %
    BatangChe                                 Modern      Regular        Central European        16 x 32   40 %
    BatangChe                                 Modern      Regular        Cyrillic                16 x 32   40 %
    BatangChe                                 Modern      Regular        Greek                   16 x 32   40 %
    BatangChe                                 Modern      Regular        Hangul                  16 x 32   40 %
    BatangChe                                 Modern      Regular        Turkish                 16 x 32   40 %
    BatangChe                                 Modern      Regular        Western                 16 x 32   40 %
    Browallia New                             Swiss       Regular        Thai                     9 x 40   40 %
    Browallia New                             Swiss       Regular        Western                  9 x 40   40 %
    BrowalliaUPC                              Swiss       Regular        Thai                     9 x 40   40 %
    Comic Sans MS                             Script      Regular        Baltic                  15 x 45   40 %
    Comic Sans MS                             Script      Regular        Central European        15 x 45   40 %
    Comic Sans MS                             Script      Regular        Cyrillic                15 x 45   40 %
    Comic Sans MS                             Script      Regular        Greek                   15 x 45   40 %
    Comic Sans MS                             Script      Regular        Turkish                 15 x 45   40 %
    Comic Sans MS                             Script      Regular        Western                 15 x 45   40 %
    Cordia New                                Swiss       Regular        Thai                     9 x 44   40 %
    Cordia New                                Swiss       Regular        Western                  9 x 44   40 %
    CordiaUPC                                 Swiss       Regular        Thai                     9 x 44   40 %
    Courier New                               Modern      Regular        Arabic                  19 x 36   40 %
    Courier New                               Modern      Regular        Baltic                  19 x 36   40 %
    Courier New                               Modern      Regular        Central European        19 x 36   40 %
    Courier New                               Modern      Regular        Cyrillic                19 x 36   40 %
    Courier New                               Modern      Regular        Greek                   19 x 36   40 %
    Courier New                               Modern      Regular        Hebrew                  19 x 36   40 %
    Courier New                               Modern      Regular        Turkish                 19 x 36   40 %
    Courier New                               Modern      Regular        Vietnamese              19 x 36   40 %
    Courier New                               Modern      Regular        Western                 19 x 36   40 %
    Courier                                   Modern                     Western                  8 x 13   40 %
    David Transparent                         Special     Regular        Hebrew                  13 x 38   40 %
    David                                     Special     Regular        Hebrew                  13 x 31   40 %
    DilleniaUPC                               Roman       Regular        Thai                     9 x 42   40 %
    Dotum                                     Swiss       Regular        Baltic                  16 x 32   40 %
    Dotum                                     Swiss       Regular        Central European        16 x 32   40 %
    Dotum                                     Swiss       Regular        Cyrillic                16 x 32   40 %
    Dotum                                     Swiss       Regular        Greek                   16 x 32   40 %
    Dotum                                     Swiss       Regular        Hangul                  16 x 32   40 %
    Dotum                                     Swiss       Regular        Turkish                 16 x 32   40 %
    Dotum                                     Swiss       Regular        Western                 16 x 32   40 %
    DotumChe                                  Modern      Regular        Baltic                  16 x 32   40 %
    DotumChe                                  Modern      Regular        Central European        16 x 32   40 %
    DotumChe                                  Modern      Regular        Cyrillic                16 x 32   40 %
    DotumChe                                  Modern      Regular        Greek                   16 x 32   40 %
    DotumChe                                  Modern      Regular        Hangul                  16 x 32   40 %
    DotumChe                                  Modern      Regular        Turkish                 16 x 32   40 %
    DotumChe                                  Modern      Regular        Western                 16 x 32   40 %
    Estrangelo Edessa                         Script      Regular        Other                   13 x 32   40 %
    EucrosiaUPC                               Roman       Regular        Thai                     9 x 39   40 %
    Fixed Miriam Transparent                  Modern      Regular        Hebrew                  19 x 36   40 %
    Fixedsys                                  Modern                     Western                  8 x 15   40 %
    Franklin Gothic Medium                    Swiss       Regular        Baltic                  14 x 36   40 %
    Franklin Gothic Medium                    Swiss       Regular        Central European        14 x 36   40 %
    Franklin Gothic Medium                    Swiss       Regular        Cyrillic                14 x 36   40 %
    Franklin Gothic Medium                    Swiss       Regular        Greek                   14 x 36   40 %
    Franklin Gothic Medium                    Swiss       Regular        Turkish                 14 x 36   40 %
    Franklin Gothic Medium                    Swiss       Regular        Western                 14 x 36   40 %
    FrankRuehl                                Special     Regular        Hebrew                  13 x 30   40 %
    FreesiaUPC                                Swiss       Regular        Thai                     9 x 38   40 %
    Gautami                                   Special     Regular        Other                   13 x 56   40 %
    Georgia                                   Roman       Regular        Baltic                  14 x 36   40 %
    Georgia                                   Roman       Regular        Central European        14 x 36   40 %
    Georgia                                   Roman       Regular        Cyrillic                14 x 36   40 %
    Georgia                                   Roman       Regular        Greek                   14 x 36   40 %
    Georgia                                   Roman       Regular        Turkish                 14 x 36   40 %
    Georgia                                   Roman       Regular        Western                 14 x 36   40 %
    Gulim                                     Swiss       Regular        Baltic                  16 x 32   40 %
    Gulim                                     Swiss       Regular        Central European        16 x 32   40 %
    Gulim                                     Swiss       Regular        Cyrillic                16 x 32   40 %
    Gulim                                     Swiss       Regular        Greek                   16 x 32   40 %
    Gulim                                     Swiss       Regular        Hangul                  16 x 32   40 %
    Gulim                                     Swiss       Regular        Turkish                 16 x 32   40 %
    Gulim                                     Swiss       Regular        Western                 16 x 32   40 %
    GulimChe                                  Modern      Regular        Baltic                  16 x 32   40 %
    GulimChe                                  Modern      Regular        Central European        16 x 32   40 %
    GulimChe                                  Modern      Regular        Cyrillic                16 x 32   40 %
    GulimChe                                  Modern      Regular        Greek                   16 x 32   40 %
    GulimChe                                  Modern      Regular        Hangul                  16 x 32   40 %
    GulimChe                                  Modern      Regular        Turkish                 16 x 32   40 %
    GulimChe                                  Modern      Regular        Western                 16 x 32   40 %
    Gungsuh                                   Roman       Regular        Baltic                  16 x 32   40 %
    Gungsuh                                   Roman       Regular        Central European        16 x 32   40 %
    Gungsuh                                   Roman       Regular        Cyrillic                16 x 32   40 %
    Gungsuh                                   Roman       Regular        Greek                   16 x 32   40 %
    Gungsuh                                   Roman       Regular        Hangul                  16 x 32   40 %
    Gungsuh                                   Roman       Regular        Turkish                 16 x 32   40 %
    Gungsuh                                   Roman       Regular        Western                 16 x 32   40 %
    GungsuhChe                                Modern      Regular        Baltic                  16 x 32   40 %
    GungsuhChe                                Modern      Regular        Central European        16 x 32   40 %
    GungsuhChe                                Modern      Regular        Cyrillic                16 x 32   40 %
    GungsuhChe                                Modern      Regular        Greek                   16 x 32   40 %
    GungsuhChe                                Modern      Regular        Hangul                  16 x 32   40 %
    GungsuhChe                                Modern      Regular        Turkish                 16 x 32   40 %
    GungsuhChe                                Modern      Regular        Western                 16 x 32   40 %
    Impact                                    Swiss       Regular        Baltic                  13 x 39   40 %
    Impact                                    Swiss       Regular        Central European        13 x 39   40 %
    Impact                                    Swiss       Regular        Cyrillic                13 x 39   40 %
    Impact                                    Swiss       Regular        Greek                   13 x 39   40 %
    Impact                                    Swiss       Regular        Turkish                 13 x 39   40 %
    Impact                                    Swiss       Regular        Western                 13 x 39   40 %
    IrisUPC                                   Swiss       Regular        Thai                     9 x 40   40 %
    JasmineUPC                                Roman       Regular        Thai                     9 x 34   40 %
    KodchiangUPC                              Roman       Regular        Thai                     9 x 31   40 %
    Latha                                     Special     Regular        Other                   29 x 44   40 %
    Levenim MT                                Special     Regular        Hebrew                  16 x 42   40 %
    LilyUPC                                   Swiss       Regular        Thai                     9 x 30   40 %
    Lucida Console                            Modern      Regular        Central European        19 x 32   40 %
    Lucida Console                            Modern      Regular        Cyrillic                19 x 32   40 %
    Lucida Console                            Modern      Regular        Greek                   19 x 32   40 %
    Lucida Console                            Modern      Regular        Turkish                 19 x 32   40 %
    Lucida Console                            Modern      Regular        Western                 19 x 32   40 %
    Lucida Sans Unicode                       Swiss       Regular        Central European        16 x 49   40 %
    Lucida Sans Unicode                       Swiss       Regular        Cyrillic                16 x 49   40 %
    Lucida Sans Unicode                       Swiss       Regular        Greek                   16 x 49   40 %
    Lucida Sans Unicode                       Swiss       Regular        Hebrew                  16 x 49   40 %
    Lucida Sans Unicode                       Swiss       Regular        Turkish                 16 x 49   40 %
    Lucida Sans Unicode                       Swiss       Regular        Western                 16 x 49   40 %
    Mangal                                    Special     Regular        Other                   18 x 54   40 %
    Marlett                                   Special     Regular        Symbol                  31 x 32   50 %
    Microsoft Sans Serif                      Swiss       Regular        Arabic                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Baltic                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Central European        14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Cyrillic                14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Greek                   14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Hebrew                  14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Thai                    14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Turkish                 14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Vietnamese              14 x 36   40 %
    Microsoft Sans Serif                      Swiss       Regular        Western                 14 x 36   40 %
    MingLiU                                   Modern      Regular        CHINESE_BIG5            16 x 32   40 %
    MingLiU                                   Modern      Regular        Western                 16 x 32   40 %
    Miriam Fixed                              Modern      Regular        Hebrew                  19 x 32   40 %
    Miriam Transparent                        Special     Regular        Hebrew                  13 x 39   40 %
    Miriam                                    Special     Regular        Hebrew                  13 x 32   40 %
    Modern                                    Modern                     OEM/DOS                 19 x 37   40 %
    MS Dialog Light                           Swiss                      Western                  7 x 10   40 %
    MS Dialog                                 Swiss                      Western                  8 x 10   70 %
    MS Gothic                                 Modern      Regular        Baltic                  16 x 32   40 %
    MS Gothic                                 Modern      Regular        Central European        16 x 32   40 %
    MS Gothic                                 Modern      Regular        Cyrillic                16 x 32   40 %
    MS Gothic                                 Modern      Regular        Greek                   16 x 32   40 %
    MS Gothic                                 Modern      Regular        Japanese                16 x 32   40 %
    MS Gothic                                 Modern      Regular        Turkish                 16 x 32   40 %
    MS Gothic                                 Modern      Regular        Western                 16 x 32   40 %
    MS Mincho                                 Modern      Regular        Baltic                  16 x 32   40 %
    MS Mincho                                 Modern      Regular        Central European        16 x 32   40 %
    MS Mincho                                 Modern      Regular        Cyrillic                16 x 32   40 %
    MS Mincho                                 Modern      Regular        Greek                   16 x 32   40 %
    MS Mincho                                 Modern      Regular        Japanese                16 x 32   40 %
    MS Mincho                                 Modern      Regular        Turkish                 16 x 32   40 %
    MS Mincho                                 Modern      Regular        Western                 16 x 32   40 %
    MS PGothic                                Swiss       Regular        Baltic                  13 x 32   40 %
    MS PGothic                                Swiss       Regular        Central European        13 x 32   40 %
    MS PGothic                                Swiss       Regular        Cyrillic                13 x 32   40 %
    MS PGothic                                Swiss       Regular        Greek                   13 x 32   40 %
    MS PGothic                                Swiss       Regular        Japanese                13 x 32   40 %
    MS PGothic                                Swiss       Regular        Turkish                 13 x 32   40 %
    MS PGothic                                Swiss       Regular        Western                 13 x 32   40 %
    MS PMincho                                Roman       Regular        Baltic                  13 x 32   40 %
    MS PMincho                                Roman       Regular        Central European        13 x 32   40 %
    MS PMincho                                Roman       Regular        Cyrillic                13 x 32   40 %
    MS PMincho                                Roman       Regular        Greek                   13 x 32   40 %
    MS PMincho                                Roman       Regular        Japanese                13 x 32   40 %
    MS PMincho                                Roman       Regular        Turkish                 13 x 32   40 %
    MS PMincho                                Roman       Regular        Western                 13 x 32   40 %
    MS Sans Serif                             Swiss                      Western                  5 x 13   40 %
    MS Serif                                  Roman                      Western                  4 x 10   40 %
    MS SystemEx                               Swiss                      Western                  9 x 12   70 %
    MS UI Gothic                              Swiss       Regular        Baltic                  13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Central European        13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Cyrillic                13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Greek                   13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Japanese                13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Turkish                 13 x 32   40 %
    MS UI Gothic                              Swiss       Regular        Western                 13 x 32   40 %
    MV Boli                                   Special     Regular        Other                   16 x 52   40 %
    Narkisim                                  Special     Regular        Hebrew                  12 x 32   40 %
    NSimSun                                   Modern      Regular        CHINESE_GB2312          16 x 32   40 %
    NSimSun                                   Modern      Regular        Western                 16 x 32   40 %
    Palatino Linotype                         Roman       Regular        Baltic                  14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Central European        14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Cyrillic                14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Greek                   14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Turkish                 14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Vietnamese              14 x 43   40 %
    Palatino Linotype                         Roman       Regular        Western                 14 x 43   40 %
    PMingLiU                                  Roman       Regular        CHINESE_BIG5            16 x 32   40 %
    PMingLiU                                  Roman       Regular        Western                 16 x 32   40 %
    Raavi                                     Special     Regular        Other                   18 x 53   40 %
    Rod Transparent                           Modern      Regular        Hebrew                  19 x 36   40 %
    Rod                                       Modern      Regular        Hebrew                  19 x 31   40 %
    Roman                                     Roman                      OEM/DOS                 22 x 37   40 %
    Script                                    Script                     OEM/DOS                 16 x 36   40 %
    Shruti                                    Special     Regular        Other                   19 x 54   40 %
    SimHei                                    Special     Regular        CHINESE_GB2312          16 x 32   40 %
    Simplified Arabic Fixed                   Modern      Regular        Arabic                  19 x 35   40 %
    Simplified Arabic                         Special     Regular        Arabic                  13 x 53   40 %
    SimSun                                    Special     Regular        CHINESE_GB2312          16 x 32   40 %
    SimSun                                    Special     Regular        Western                 16 x 32   40 %
    Small Fonts                               Swiss                      Western                   1 x 3   40 %
    Sylfaen                                   Roman       Regular        Baltic                  13 x 42   40 %
    Sylfaen                                   Roman       Regular        Central European        13 x 42   40 %
    Sylfaen                                   Roman       Regular        Cyrillic                13 x 42   40 %
    Sylfaen                                   Roman       Regular        Greek                   13 x 42   40 %
    Sylfaen                                   Roman       Regular        Turkish                 13 x 42   40 %
    Sylfaen                                   Roman       Regular        Western                 13 x 42   40 %
    Symbol                                    Roman       Regular        Symbol                  19 x 39   40 %
    System                                    Swiss                      Western                  7 x 16   70 %
    Tahoma                                    Swiss       Bold           Arabic                  16 x 39   70 %
    Tahoma                                    Swiss       Bold           Baltic                  16 x 39   70 %
    Tahoma                                    Swiss       Bold           Central European        16 x 39   70 %
    Tahoma                                    Swiss       Bold           Cyrillic                16 x 39   70 %
    Tahoma                                    Swiss       Bold           Greek                   16 x 39   70 %
    Tahoma                                    Swiss       Bold           Hebrew                  16 x 39   70 %
    Tahoma                                    Swiss       Bold           Thai                    16 x 39   70 %
    Tahoma                                    Swiss       Bold           Turkish                 16 x 39   70 %
    Tahoma                                    Swiss       Bold           Vietnamese              16 x 39   70 %
    Tahoma                                    Swiss       Bold           Western                 16 x 39   70 %
    Terminal                                  Modern                     OEM/DOS                  8 x 12   40 %
    Times New Roman                           Roman       Regular        Arabic                  13 x 35   40 %
    Times New Roman                           Roman       Regular        Baltic                  13 x 35   40 %
    Times New Roman                           Roman       Regular        Central European        13 x 35   40 %
    Times New Roman                           Roman       Regular        Cyrillic                13 x 35   40 %
    Times New Roman                           Roman       Regular        Greek                   13 x 35   40 %
    Times New Roman                           Roman       Regular        Hebrew                  13 x 35   40 %
    Times New Roman                           Roman       Regular        Turkish                 13 x 35   40 %
    Times New Roman                           Roman       Regular        Vietnamese              13 x 35   40 %
    Times New Roman                           Roman       Regular        Western                 13 x 35   40 %
    Traditional Arabic                        Special     Regular        Arabic                  13 x 48   40 %
    Trebuchet MS                              Swiss       Regular        Baltic                  15 x 37   40 %
    Trebuchet MS                              Swiss       Regular        Central European        15 x 37   40 %
    Trebuchet MS                              Swiss       Regular        Cyrillic                15 x 37   40 %
    Trebuchet MS                              Swiss       Regular        Greek                   15 x 37   40 %
    Trebuchet MS                              Swiss       Regular        Turkish                 15 x 37   40 %
    Trebuchet MS                              Swiss       Regular        Western                 15 x 37   40 %
    Tunga                                     Special     Regular        Other                   17 x 53   40 %
    Verdana                                   Swiss       Regular        Baltic                  16 x 39   40 %
    Verdana                                   Swiss       Regular        Central European        16 x 39   40 %
    Verdana                                   Swiss       Regular        Cyrillic                16 x 39   40 %
    Verdana                                   Swiss       Regular        Greek                   16 x 39   40 %
    Verdana                                   Swiss       Regular        Turkish                 16 x 39   40 %
    Verdana                                   Swiss       Regular        Vietnamese              16 x 39   40 %
    Verdana                                   Swiss       Regular        Western                 16 x 39   40 %
    Webdings                                  Roman       Regular        Symbol                  31 x 32   40 %
    Wingdings                                 Special     Regular        Symbol                  28 x 36   40 %
    WST_Czec                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Engl                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Fren                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Germ                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Ital                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Span                                  Decorative                 Symbol                  10 x 12   70 %
    WST_Swed                                  Decorative                 Symbol                  10 x 12   70 %


--------[ Audio Codecs ]------------------------------------------------------------------------------------------------

  [ DSP Group TrueSpeech(TM) Software CODEC ]

    ACM Driver Properties:
      Driver Description                                DSP Group TrueSpeech(TM) Software CODEC
      Copyright Notice                                  Copyright (C) 1993-1996 DSP Group, Inc.
      License Information                               TrueSpeech is a trademark of DSP Group, Inc., Santa Clara, California.
      Driver Features                                   Compresses and decompresses DSP Group TrueSpeech(TM) audio data.
      Driver Version                                    1.00

  [ Fraunhofer IIS MPEG Layer-3 Codec (advanced) ]

    ACM Driver Properties:
      Driver Description                                Fraunhofer IIS MPEG Layer-3 Codec (advanced)
      Copyright Notice                                  Copyright  1996-1999 Fraunhofer Institut Integrierte Schaltungen IIS
      Driver Features                                   bitrates up to 56kBit/s, mono and stereo codec (advanced)
      Driver Version                                    1.09

  [ Microsoft ADPCM CODEC ]

    ACM Driver Properties:
      Driver Description                                Microsoft ADPCM CODEC
      Copyright Notice                                  Copyright (C) 1992-1996 Microsoft Corporation
      Driver Features                                   Compresses and decompresses Microsoft ADPCM audio data.
      Driver Version                                    4.00

  [ Microsoft CCITT G.711 A-Law and u-Law CODEC ]

    ACM Driver Properties:
      Driver Description                                Microsoft CCITT G.711 A-Law and u-Law CODEC
      Copyright Notice                                  Copyright (c) 1993-1996 Microsoft Corporation
      Driver Features                                   Compresses and decompresses CCITT G.711 A-Law and u-Law audio data.
      Driver Version                                    4.00

  [ Microsoft G.723.1 CODEC ]

    ACM Driver Properties:
      Driver Description                                Microsoft G.723.1 CODEC
      Copyright Notice                                  Copyright  1996 Intel Corporation and Microsoft Corporation
      Driver Features                                   Compresses and decompresses G.723.1 audio data.
      Driver Version                                    1.02

  [ Microsoft GSM 6.10 Audio CODEC ]

    ACM Driver Properties:
      Driver Description                                Microsoft GSM 6.10 Audio CODEC
      Copyright Notice                                  Copyright (C) 1993-1996 Microsoft Corporation
      Driver Features                                   Compresses and decompresses audio data conforming to the ETSI-GSM (European Telecommunications Standards Institute-Groupe Special Mobile) recommendation 6.10.
      Driver Version                                    4.00

  [ Microsoft IMA ADPCM CODEC ]

    ACM Driver Properties:
      Driver Description                                Microsoft IMA ADPCM CODEC
      Copyright Notice                                  Copyright (C) 1992-1996 Microsoft Corporation
      Driver Features                                   Compresses and decompresses IMA ADPCM audio data.
      Driver Version                                    4.00

  [ Microsoft PCM Converter ]

    ACM Driver Properties:
      Driver Description                                Microsoft PCM Converter
      Copyright Notice                                  Copyright (C) 1992-1996 Microsoft Corporation
      Driver Features                                   Converts frequency and bits per sample of PCM audio data.
      Driver Version                                    5.00

  [ Sipro Lab Telecom ACELP.net audio codec ]

    ACM Driver Properties:
      Driver Description                                Sipro Lab Telecom ACELP.net audio codec
      Copyright Notice                                  Copyright  1995-99 Sipro Lab Telecom Inc., Montreal
      Driver Features                                   ACELP.net audio encoder/decoder. For licensing please access  HTTP: //www.sipro.com
      Driver Version                                    3.02

  [ Windows Media Audio ]

    ACM Driver Properties:
      Driver Description                                Windows Media Audio
      Copyright Notice                                  Copyright (C) Microsoft Corporation, 1999 - 2001
      Driver Features                                   Compresses and decompresses audio data.
      Driver Version                                    4.02


--------[ Video Codecs ]------------------------------------------------------------------------------------------------

    iyuv_32.dll                5.2.3790.3959 (srv03_sp2_rtm.070216-1710)  Intel Indeo(R) Video YUV Codec
    msh261.drv                 5.2.3790.3959                       Microsoft H.261 ICM Driver
    msh263.drv                 5.2.3790.3959                       Microsoft H.263 ICM Driver
    msrle32.dll                5.2.3790.0 (srv03_rtm.030324-2048)  Microsoft RLE Compressor
    msvidc32.dll               5.2.3790.0 (srv03_rtm.030324-2048)  Microsoft Video 1 Compressor
    msyuv.dll                  5.2.3790.0 (srv03_rtm.030324-2048)  Microsoft UYVY Video Decompressor
    tsbyuv.dll                 5.2.3790.0 (srv03_rtm.030324-2048)  Toshiba Video Codec


--------[ MCI ]---------------------------------------------------------------------------------------------------------

  [ AVIVideo ]

    MCI Device Properties:
      Device                                            AVIVideo
      Name                                              Video for Windows
      Description                                       Video For Windows MCI driver
      Type                                              Digital Video Device
      Driver                                            mciavi32.dll
      Status                                            Enabled

    MCI Device Features:
      Compound Device                                   Yes
      File Based Device                                 Yes
      Can Eject                                         No
      Can Play                                          Yes
      Can Play In Reverse                               Yes
      Can Record                                        No
      Can Save Data                                     No
      Can Freeze Data                                   No
      Can Lock Data                                     No
      Can Stretch Frame                                 Yes
      Can Stretch Input                                 No
      Can Test                                          Yes
      Audio Capable                                     Yes
      Video Capable                                     Yes
      Still Image Capable                               No

  [ CDAudio ]

    MCI Device Properties:
      Device                                            CDAudio
      Description                                       MCI driver for cdaudio devices
      Driver                                            mcicda.dll
      Status                                            Enabled

  [ MPEGVideo ]

    MCI Device Properties:
      Device                                            MPEGVideo
      Name                                              DirectShow
      Description                                       DirectShow MCI Driver
      Type                                              Digital Video Device
      Driver                                            mciqtz32.dll
      Status                                            Enabled

    MCI Device Features:
      Compound Device                                   Yes
      File Based Device                                 Yes
      Can Eject                                         No
      Can Play                                          Yes
      Can Play In Reverse                               No
      Can Record                                        No
      Can Save Data                                     No
      Can Freeze Data                                   No
      Can Lock Data                                     No
      Can Stretch Frame                                 Yes
      Can Stretch Input                                 No
      Can Test                                          Yes
      Audio Capable                                     Yes
      Video Capable                                     Yes
      Still Image Capable                               No

  [ Sequencer ]

    MCI Device Properties:
      Device                                            Sequencer
      Name                                              MIDI Sequencer
      Description                                       MCI driver for MIDI sequencer
      Type                                              Sequencer Device
      Driver                                            mciseq.dll
      Status                                            Enabled

    MCI Device Features:
      Compound Device                                   No
      File Based Device                                 No
      Can Eject                                         No
      Can Play                                          No
      Can Record                                        No
      Can Save Data                                     No
      Audio Capable                                     No
      Video Capable                                     No

  [ WaveAudio ]

    MCI Device Properties:
      Device                                            WaveAudio
      Name                                              Sound
      Description                                       MCI driver for waveform audio
      Type                                              Waveform Audio Device
      Driver                                            mciwave.dll
      Status                                            Enabled

    MCI Device Features:
      Compound Device                                   Yes
      File Based Device                                 Yes
      Can Eject                                         No
      Can Play                                          Yes
      Can Record                                        No
      Can Save Data                                     Yes
      Audio Capable                                     Yes
      Video Capable                                     No


--------[ IAM ]---------------------------------------------------------------------------------------------------------

  [ Active Directory ]

    Account Properties:
      Account Name                                      Active Directory
      Account ID                                        Active Directory GC
      Account Type                                      LDAP (Default)
      Connection Name                                   Not Specified (IE Default)
      LDAP Server                                       NULL:3268
      LDAP User Name                                    NULL
      LDAP Search Base                                  NULL
      LDAP Search Timeout                               1 min

    Account Features:
      LDAP Authentication Required                      Yes
      LDAP Secure Authentication                        Yes
      LDAP Secure Connection                            No
      LDAP Simple Search Filter                         No

  [ Bigfoot Internet Directory Service ]

    Account Properties:
      Account Name                                      Bigfoot Internet Directory Service
      Account ID                                        Bigfoot
      Account Type                                      LDAP
      Connection Name                                   Not Specified (IE Default)
      LDAP Server                                       ldap.bigfoot.com
      LDAP URL                                          http://www.bigfoot.com
      LDAP Search Timeout                               1 min

    Account Features:
      LDAP Authentication Required                      No
      LDAP Secure Authentication                        No
      LDAP Secure Connection                            No
      LDAP Simple Search Filter                         Yes

  [ VeriSign Internet Directory Service ]

    Account Properties:
      Account Name                                      VeriSign Internet Directory Service
      Account ID                                        VeriSign
      Account Type                                      LDAP
      Connection Name                                   Not Specified (IE Default)
      LDAP Server                                       directory.verisign.com
      LDAP URL                                          http://www.verisign.com
      LDAP Search Base                                  NULL
      LDAP Search Timeout                               1 min

    Account Features:
      LDAP Authentication Required                      No
      LDAP Secure Authentication                        No
      LDAP Secure Connection                            No
      LDAP Simple Search Filter                         Yes

  [ WhoWhere Internet Directory Service ]

    Account Properties:
      Account Name                                      WhoWhere Internet Directory Service
      Account ID                                        WhoWhere
      Account Type                                      LDAP
      Connection Name                                   Not Specified (IE Default)
      LDAP Server                                       ldap.whowhere.com
      LDAP URL                                          http://www.whowhere.com
      LDAP Search Timeout                               1 min

    Account Features:
      LDAP Authentication Required                      No
      LDAP Secure Authentication                        No
      LDAP Secure Connection                            No
      LDAP Simple Search Filter                         Yes


--------[ Internet ]----------------------------------------------------------------------------------------------------

    Internet Settings:
      Start Page                                        http://go.microsoft.com/fwlink/?LinkId=93140
      Search Page                                       http://www.google.com
      Download Folder                                   

    Current Proxy:
      Proxy Status                                      Disabled

    LAN Proxy:
      Proxy Status                                      Disabled


--------[ Routes ]------------------------------------------------------------------------------------------------------

    Active                0.0.0.0          0.0.0.0      192.168.0.1  20   192.168.0.11 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - cFosSpeed Miniport)
    Active              127.0.0.0        255.0.0.0        127.0.0.1  1    127.0.0.1 (MS TCP Loopback interface)
    Active            192.168.0.0    255.255.255.0     192.168.0.11  20   192.168.0.11 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - cFosSpeed Miniport)
    Active           192.168.0.11  255.255.255.255        127.0.0.1  20   127.0.0.1 (MS TCP Loopback interface)
    Active          192.168.0.255  255.255.255.255     192.168.0.11  20   192.168.0.11 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - cFosSpeed Miniport)
    Active              224.0.0.0        240.0.0.0     192.168.0.11  20   192.168.0.11 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - cFosSpeed Miniport)
    Active        255.255.255.255  255.255.255.255     192.168.0.11  1    192.168.0.11 (Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC - cFosSpeed Miniport)


--------[ IE Cookie ]---------------------------------------------------------------------------------------------------

    2008-01-14 21:54:39  administrator@download.mozilla.org/
    2008-01-14 22:35:53  administrator@update.microsoft.com/
    2008-01-15 06:00:53  administrator@rad.microsoft.com/
    2008-01-15 06:04:27  administrator@rad.msn.com/
    2008-01-15 06:04:31  administrator@atdmt.com/
    2008-01-15 06:05:04  administrator@search.microsoft.com/
    2008-01-15 06:05:38  administrator@microsoftwlmessengermkt.112.2o7.net/
    2008-01-15 23:19:24  administrator@onlinestores.metaservices.microsoft.com/serviceswitching/
    2008-01-15 23:19:27  administrator@img.mixplay.tv/
    2008-01-15 23:19:27  administrator@live365.com/
    2008-01-23 19:46:31  administrator@www.microsoft.com/
    2008-01-23 19:46:32  administrator@m.webtrends.com/
    2008-03-16 14:26:35  administrator@microsoft.com/


--------[ Browser History ]---------------------------------------------------------------------------------------------

    2008-01-15 04:44:07  Administrator@about:Home
    2008-03-16 13:42:59  Administrator@file:///C:/Documents%20and%20Settings/All%20Users/Application%20Data/Microsoft/Windows%20Home%20Server/logs/qsm.031608.log
    2008-03-16 13:47:01  Administrator@res://C:\WINDOWS\System32\mmcndmgr.dll/views.htm
    2008-03-16 13:50:18  Administrator@file:///C:/Documents%20and%20Settings/All%20Users/Application%20Data/Microsoft/Windows%20Home%20Server/logs/PartnerManager.031608.log
    2008-03-16 13:50:21  Administrator@file:///C:/Documents%20and%20Settings/All%20Users/Application%20Data/Microsoft/Windows%20Home%20Server/logs/chkdsk.log
    2008-03-16 14:09:39  Administrator@file:///C:/Program%20Files/Windows%20Home%20Server/Toolkit/readme.htm
    2008-03-16 14:26:36  Administrator@http://www.serverplayground.com
    2008-03-16 14:26:49  Administrator@res://C:\WINDOWS\system32\shdoclc.dll/dnserror.htm
    2008-03-29 10:57:49  Administrator@file:///C:/Documents%20and%20Settings/Administrator/Local%20Settings/Temp/1/rpt-1.txt


--------[ DirectX Files ]-----------------------------------------------------------------------------------------------

    amstream.dll        6.05.3790.3959    Final Retail  English                       72704  2/17/2007 15:02:42
    d3d8.dll            5.03.3790.3959    Final Retail  English                     1042432  2/17/2007 15:02:48
    d3d8thk.dll         5.02.3790.0000    Final Retail  English                        8192  3/25/2003 10:48:08
    d3d9.dll            5.03.3790.3959    Final Retail  English                     1690624  2/17/2007 15:02:48
    d3dim.dll           5.02.3790.3959    Final Retail  English                      378880  2/17/2007 15:02:48
    d3dim700.dll        5.03.3790.3959    Final Retail  English                      835584  2/17/2007 15:02:48
    d3dpmesh.dll        5.02.3790.0000    Final Retail  English                       36864  3/25/2003 10:48:08
    d3dramp.dll         5.02.3790.0000    Final Retail  English                      590848  3/25/2003 10:48:08
    d3drm.dll           5.02.3790.0000    Final Retail  English                      351744  3/25/2003 10:48:08
    d3dxof.dll          5.02.3790.0000    Final Retail  English                       48128  3/25/2003 10:48:08
    ddraw.dll           5.03.3790.3959    Final Retail  English                      276480  2/17/2007 15:02:48
    ddrawex.dll         5.03.3790.3959    Final Retail  English                       27648  2/17/2007 15:02:48
    devenum.dll         6.05.3790.3959    Final Retail  English                       61440  2/17/2007 15:02:48
    diactfrm.dll        5.03.3790.3959    Final Retail  English                      415744  2/17/2007 15:02:48
    dimap.dll           5.02.3790.0000    Final Retail  English                       42496  3/25/2003 10:48:14
    dinput.dll          5.03.3790.3959    Final Retail  English                      159744  2/17/2007 15:02:48
    dinput8.dll         5.03.3790.3959    Final Retail  English                      182272  2/17/2007 15:02:48
    dplaysvr.exe        5.03.3790.3959    Final Retail  English                       31744  2/17/2007 15:03:38
    dplayx.dll          5.03.3790.3959    Final Retail  English                      230400  2/17/2007 15:02:50
    dpmodemx.dll        5.03.3790.3959    Final Retail  English                       23552  2/17/2007 15:02:50
    dpnaddr.dll         5.03.3790.3959    Final Retail  English                        3584  2/17/2007 14:59:16
    dpnet.dll           5.03.3790.3959    Final Retail  English                      376320  2/17/2007 15:02:50
    dpnhpast.dll        5.03.3790.3959    Final Retail  English                        4096  2/17/2007 15:02:50
    dpnhupnp.dll        5.03.3790.3959    Final Retail  English                       60928  2/17/2007 15:02:50
    dpnlobby.dll        5.03.3790.3959    Final Retail  English                        3584  2/17/2007 14:59:18
    dpnsvr.exe          5.03.3790.3959    Final Retail  English                       17920  2/17/2007 15:03:38
    dpvacm.dll          5.03.3790.3959    Final Retail  English                       22016  2/17/2007 15:02:50
    dpvoice.dll         5.03.3790.3959    Final Retail  English                      212480  2/17/2007 15:02:50
    dpvsetup.exe        5.03.3790.3959    Final Retail  English                       83968  2/17/2007 15:03:38
    dpvvox.dll          5.03.3790.3959    Final Retail  English                      116736  2/17/2007 15:02:50
    dpwsockx.dll        5.03.3790.3959    Final Retail  English                       57344  2/17/2007 15:02:50
    dsdmo.dll           5.03.3790.3959    Final Retail  English                      182272  2/17/2007 15:02:50
    dsdmoprp.dll        5.03.3790.3959    Final Retail  English                       75776  2/17/2007 15:02:50
    dsound.dll          5.03.3790.3959    Final Retail  English                      360960  2/17/2007 15:02:50
    dsound3d.dll        5.03.3790.3959    Final Retail  English                     1294848  2/17/2007 15:02:50
    dx7vb.dll           5.03.3790.3959    Final Retail  English                      621056  2/17/2007 15:02:50
    dx8vb.dll           5.03.3790.3959    Final Retail  English                     1225216  2/17/2007 15:02:50
    dxapi.sys           5.02.3790.0000    Final Retail  English                       12800  3/25/2003 08:06:04
    dxdiagn.dll         5.03.3790.3959    Final Retail  English                     1765376  2/17/2007 15:02:50
    dxg.sys             5.02.3790.3959    Final Retail  English                       73216  2/17/2007 07:14:44
    dxmasf.dll          6.04.09.1125      Final Retail  English                      498205  3/25/2003 10:48:20
    dxtmsft.dll         6.03.3790.4210    Final Retail  English                      361472  12/21/2007 23:59:00
    dxtrans.dll         6.03.3790.4210    Final Retail  English                      209920  12/21/2007 23:59:00
    encapi.dll          5.03.3790.3959    Final Retail  English                       20480  2/17/2007 15:02:50
    gcdef.dll           5.03.3790.3959    Final Retail  English                       80896  2/17/2007 15:02:52
    joy.cpl             5.03.3790.3959    Final Retail  English                       69632  2/17/2007 15:04:08
    ks.sys              5.03.3790.3959    Final Retail  English                      140288  2/17/2007 15:27:08
    ksuser.dll          5.03.3790.3959    Final Retail  English                        4096  2/17/2007 15:27:08
    mciqtz32.dll        6.05.3790.3959    Final Retail  English                       62464  2/17/2007 15:02:56
    mfc40.dll           4.01.00.6140      Final Retail  English                      924432  3/25/2003 10:49:16
    mfc42.dll           6.06.8063.0000    Beta Retail   English                     1160704  2/17/2007 15:02:56
    mpeg2data.ax        6.05.3790.3959    Final Retail  English                       62976  2/17/2007 15:04:10
    mpg2splt.ax         6.05.3790.3959    Final Retail  English                      148992  2/17/2007 15:04:10
    msdmo.dll           6.05.3790.3959    Final Retail  English                       14336  2/17/2007 15:03:00
    msvidctl.dll        6.05.3790.3959    Final Retail  English                      617472  2/17/2007 15:03:04
    mswebdvd.dll        6.05.3790.3959    Final Retail  English                      209408  2/17/2007 15:03:04
    msyuv.dll           5.02.3790.0000    Final Retail  English                       16896  2/18/2007 10:54:20
    pid.dll             5.02.3790.0000    Final Retail  English                       33792  2/18/2007 10:54:20
    qasf.dll            10.00.00.3997     Final Retail  English                      217088  2/17/2007 15:03:10
    qcap.dll            6.05.3790.3959    Final Retail  English                      192512  2/17/2007 15:03:10
    qdv.dll             6.05.3790.3959    Final Retail  English                      279040  2/17/2007 15:03:10
    qdvd.dll            6.05.3790.3959    Final Retail  English                      385536  2/17/2007 15:03:10
    qedit.dll           6.05.3790.3959    Final Retail  English                      512512  2/17/2007 15:03:10
    qedwipes.dll        6.05.3790.3959    Final Retail  English                      733696  2/17/2007 05:55:02
    quartz.dll          6.05.3790.4178    Final Retail  English                     1274880  10/30/2007 06:03:34
    stream.sys          5.03.3790.3959    Final Retail  English                       49408  2/17/2007 15:27:08
    strmdll.dll         4.01.00.3936      Beta Retail   English                      246814  2/17/2007 15:03:16
    swenum.sys          5.03.3790.3959    Final Retail  English                        4736  2/17/2007 15:27:08
    vbisurf.ax          5.03.3790.3959    Final Retail  English                       30720  2/17/2007 15:04:10
    wsock32.dll         5.02.3790.0000    Final Retail  English                       22528  3/25/2003 10:50:42
    wstdecod.dll        5.03.3790.3959    Final Retail  English                       50688  2/17/2007 15:03:26


--------[ Auto Start ]--------------------------------------------------------------------------------------------------

    cFosSpeed                          Registry\Common\Run      C:\Program Files\cFosSpeed\cFosSpeed.exe 
    dms_helper                         Registry\Common\Run      C:\Program Files\DiXiM Media Server\dms_helper.exe 


--------[ Scheduled ]---------------------------------------------------------------------------------------------------

  [ shutdown ]

    Task Properties:
      Task Name                                         shutdown
      Status                                            Disabled
      Application Name                                  C:\WINDOWS\system32\shutdown.exe
      Application Parameters                            -r -t 0
      Working Folder                                    C:\WINDOWS\system32
      Comment                                           
      Account Name                                      WEBERSERVER\Administrator
      Creator                                           Administrator
      Last Run                                          3/15/2008
      Next Run                                          Unknown

    Task Triggers:
      Trigger #1                                        At 00:00 every day, starting 2/27/2008

  [ shutdown2 ]

    Task Properties:
      Task Name                                         shutdown2
      Status                                            Disabled
      Application Name                                  C:\WINDOWS\system32\shutdown.exe
      Application Parameters                            -r -t 0
      Working Folder                                    C:\WINDOWS\system32
      Comment                                           
      Account Name                                      WEBERSERVER\Administrator
      Creator                                           Administrator
      Last Run                                          3/12/2008 12:00:00
      Next Run                                          Unknown

    Task Triggers:
      Trigger #1                                        At 12:00 every day, starting 2/27/2008


--------[ Installed Programs ]------------------------------------------------------------------------------------------

    Torrent                                                                                     1.7.7    216.0 KB
    7-Zip 4.57                                                                                              2.9 MB
    ATI - Software Uninstall Utility                                                      6.14.10.1016     Unknown
    ATI Display Driver                                                                8.342-070202a1-044058C-Asus     Unknown
    cFosSpeed v4.20                                                                               4.20      5.7 MB
    Client PC Information AddIn                                                                2.0.0.0    136.0 KB
    DiXiM Media Server [english (united states)]                                                2.3.11     Unknown
    Hotfix for Windows Server 2003 (KB936598-v2)                                                     2     Unknown
    Hotfix for Windows Server 2003 (KB937108-v2)                                                     2     Unknown
    Microsoft .NET Framework 2.0                                                                           88.3 MB
    Microsoft .NET Framework 2.0                                                             2.0.50727     Unknown
    Mozilla Firefox (2.0.0.11)                                                        2.0.0.11 (en-US)     19.8 MB
    Realtek High Definition Audio Driver [english (united states)]                         5.10.0.5391     Unknown
    Security Update for Microsoft .NET Framework 2.0 (KB928365)                                      2     Unknown
    Security Update for Windows Server 2003 (KB921503)                                               1     Unknown
    Security Update for Windows Server 2003 (KB924667-v2)                                            2     Unknown
    Security Update for Windows Server 2003 (KB925902)                                               1     Unknown
    Security Update for Windows Server 2003 (KB926122)                                               1     Unknown
    Security Update for Windows Server 2003 (KB930178)                                               1     Unknown
    Security Update for Windows Server 2003 (KB931784)                                               1     Unknown
    Security Update for Windows Server 2003 (KB932168)                                               1     Unknown
    Security Update for Windows Server 2003 (KB933729)                                               1     Unknown
    Security Update for Windows Server 2003 (KB933854)                                               1     Unknown
    Security Update for Windows Server 2003 (KB935839)                                               1     Unknown
    Security Update for Windows Server 2003 (KB935840)                                               1     Unknown
    Security Update for Windows Server 2003 (KB936021)                                               1     Unknown
    Security Update for Windows Server 2003 (KB936782)                                               1     Unknown
    Security Update for Windows Server 2003 (KB938127)                                               1     Unknown
    Security Update for Windows Server 2003 (KB941568)                                               1     Unknown
    Security Update for Windows Server 2003 (KB941569)                                               1     Unknown
    Security Update for Windows Server 2003 (KB941644)                                               1     Unknown
    Security Update for Windows Server 2003 (KB942615)                                               1     Unknown
    Security Update for Windows Server 2003 (KB942830)                                               1     Unknown
    Security Update for Windows Server 2003 (KB942831)                                               1     Unknown
    Security Update for Windows Server 2003 (KB943055)                                               1     Unknown
    Security Update for Windows Server 2003 (KB943485)                                               1     Unknown
    Security Update for Windows Server 2003 (KB944533)                                               1     Unknown
    Security Update for Windows Server 2003 (KB944653)                                               1     Unknown
    Security Update for Windows Server 2003 (KB946026)                                               1     Unknown
    Tweak UI                                                                                               Unknown
    Update for Windows Home Server (KB941914)                                                        1     Unknown
    Update for Windows Home Server (KB946146)                                                        1     Unknown
    Update for Windows Server 2003 (KB927891)                                                        5     Unknown
    Update for Windows Server 2003 (KB937153-v2)                                                     2     Unknown
    Update for Windows Server 2003 (KB937253-v2)                                                     2     Unknown
    Update for Windows Server 2003 (KB942763)                                                        1     Unknown
    Update for Windows Server 2003 (KB942840)                                                        1     Unknown
    Update for Windows Server 2003 (KB948496)                                                        1     Unknown
    Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)  05/27/2006 1.3.2.0     Unknown
    Windows Home Server - uTorrent                                                             1.1.1.0    220.0 KB
    Windows Home Server Activation Component                                                               16.7 MB
    Windows Home Server Backup Service                                                                     16.7 MB
    Windows Home Server Certificate Enrollment (Public Service)                                            16.7 MB
    Windows Home Server Certificate Enrollment (Setup module)                                              16.7 MB
    Windows Home Server Certificate Enrollment                                                             16.7 MB
    Windows Home Server Console                                                                            16.7 MB
    Windows Home Server Critical Process Monitor                                                           16.7 MB
    Windows Home Server Drive Extender                                                                     16.7 MB
    Windows Home Server Dynamic DNS Service                                                                16.7 MB
    Windows Home Server Event Parser                                                                       16.7 MB
    Windows Home Server Notification Service                                                               16.7 MB
    Windows Home Server OOBE Setup Module                                                                  16.7 MB
    Windows Home Server Port Forwarding Service                                                            16.7 MB
    Windows Home Server Preserver                                                                          16.7 MB
    Windows Home Server Remote Access (Base Package)                                                       16.7 MB
    Windows Home Server Remote Access (Public)                                                             16.7 MB
    Windows Home Server Remote Access (RWW)                                                                16.7 MB
    Windows Home Server SDK                                                                                16.7 MB
    Windows Home Server Storage Service                                                                    16.7 MB
    Windows Home Server Toolkit                                                             6.0.1639.0     Unknown
    Windows Home Server Transport Service                                                                  16.7 MB
    Windows Home Server UPnP and Media Connect Pack                                                        16.7 MB
    Windows Resource Kit Tools                                                                5.2.3790     18.7 MB
    xplorer lite                                                                                1.7 L      1.7 MB


--------[ Licenses ]----------------------------------------------------------------------------------------------------

    Microsoft Internet Explorer 6.0.3790.3959                               P2H7J-VDDX2-KKVFY-TVWKK-F43JD
    Microsoft Windows Small Business Server 2003 Standard Edition        P2H7J-VDDX2-KKVFY-TVWKK-F43JD


--------[ File Types ]--------------------------------------------------------------------------------------------------

    323               H.323 Internet Telephony                                         text/h323
    386               Virtual device driver                                            
    ACA               Microsoft Agent Character File (HTTP format)                     
    ACF               Microsoft Agent Character File (HTTP format)                     
    ACS               Microsoft Agent Character File                                   
    AIF               AIFF Format Sound                                                audio/aiff
    AIFC              AIFF Format Sound                                                audio/aiff
    AIFF              AIFF Format Sound                                                audio/aiff
    ANI               Animated Cursor                                                  
    APPLICATION       Application Manifest                                             application/x-ms-application
    APPREF-MS         Application Reference                                            
    ASA               ASA File                                                         
    ASF               Windows Media Audio/Video file                                   video/x-ms-asf
    ASP               ASP File                                                         
    ASX               Windows Media Audio/Video playlist                               video/x-ms-asf
    AU                AU Format Sound                                                  audio/basic
    AVI               Video Clip                                                       video/avi
    BAT               Windows Batch File                                               
    BFC               Briefcase                                                        
    BKF               Microsoft Backup File                                            
    BLG               BLG File                                                         
    CAB               Cabinet File                                                     
    CAT               Security Catalog                                                 application/vnd.ms-pki.seccat
    CDA               CD Audio Track                                                   
    CDF               Channel File                                                     application/x-cdf
    CDX               CDX File                                                         
    CER               Security Certificate                                             application/x-x509-ca-cert
    CFOSSPEED         cFosSpeed Registration Key                                       
    CHK               Recovered File Fragments                                         
    CHM               Compiled HTML Help file                                          
    CLP               Clipboard Clip                                                   
    CMD               Windows Command Script                                           
    CNF               SpeedDial                                                        
    COM               Application                                                      
    CPL               Control Panel extension                                          
    CRL               Certificate Revocation List                                      application/pkix-crl
    CRT               Security Certificate                                             application/x-x509-ca-cert
    CSS               Cascading Style Sheet Document                                   text/css
    CUR               Cursor                                                           
    DB                Data Base File                                                   
    DER               Security Certificate                                             application/x-x509-ca-cert
    DESKLINK          DESKLINK File                                                    
    DIB               DIB File                                                         image/bmp
    DLL               Application Extension                                            application/x-msdownload
    DOC               DOC File                                                         
    DRV               Device driver                                                    
    DSN               Microsoft OLE DB Provider for ODBC Drivers                       
    DUN               Dialup Networking File                                           
    DVR-MS            Microsoft Recorded TV Show                                       
    EMF               EMF File                                                         
    EML               Internet E-Mail Message                                          message/rfc822
    EVT               EVT File                                                         
    EXE               Application                                                      application/x-msdownload
    FND               Saved Search                                                     
    FON               Font file                                                        
    GIF               GIF Image                                                        image/gif
    GRP               Microsoft Program Group                                          
    HLP               Help File                                                        
    HTA               HTML Application                                                 application/hta
    HTM               Firefox Document                                                 text/html
    HTML              Firefox Document                                                 text/html
    HTT               HyperText Template                                               text/webviewhtml
    ICC               ICC Profile                                                      
    ICM               ICC Profile                                                      
    ICO               Icon                                                             image/x-icon
    III               Intel IPhone Compatible                                          application/x-iphone
    INF               Setup Information                                                
    INI               Configuration Settings                                           
    INS               Internet Communication Settings                                  application/x-internet-signup
    ISP               Internet Communication Settings                                  application/x-internet-signup
    ITS               Internet Document Set                                            
    JFIF              JPEG Image                                                       image/jpeg
    JOB               Task Scheduler Task Object                                       
    JOD               Microsoft.Jet.OLEDB.4.0                                          
    JPE               JPEG Image                                                       image/jpeg
    JPEG              JPEG Image                                                       image/jpeg
    JPG               JPEG Image                                                       image/jpeg
    JS                JScript Script File                                              
    JSE               JScript Encoded Script File                                      
    LNK               Shortcut                                                         
    LOG               Text Document                                                    
    LWV               Microsoft Linguistically Enhanced Sound File                     
    M1V               Movie Clip                                                       video/mpeg
    M3U               M3U file                                                         audio/x-mpegurl
    MAPIMAIL          MAPIMAIL File                                                    
    MHT               MHTML Document                                                   message/rfc822
    MHTML             MHTML Document                                                   message/rfc822
    MID               MIDI Sequence                                                    audio/mid
    MIDI              MIDI Sequence                                                    audio/mid
    MMM               Media Clip                                                       
    MP2               Movie Clip                                                       video/mpeg
    MP2V              Movie Clip                                                       video/mpeg
    MP3               MP3 Format Sound                                                 audio/mpeg
    MPA               Movie Clip                                                       video/mpeg
    MPE               Movie Clip                                                       video/mpeg
    MPEG              Movie Clip                                                       video/mpeg
    MPG               Movie Clip                                                       video/mpeg
    MPV2              Movie Clip                                                       video/mpeg
    MSC               Microsoft Common Console Document                                
    MSI               Windows Installer Package                                        
    MSP               Windows Installer Patch                                          
    MSRCINCIDENT      MSRCINCIDENT File                                                
    MSSTYLES          Windows Visual Style File                                        
    MYDOCS            MyDocs Drop Target                                               
    NFO               MSInfo File                                                      
    NMW               Microsoft Netmeeting T126 Compatible Whiteboard Document         application/nmwb
    NWS               Internet News Message                                            message/rfc822
    OCX               ActiveX Control                                                  
    OTF               OpenType Font file                                               
    P10               Certificate Request                                              application/pkcs10
    P12               Personal Information Exchange                                    application/x-pkcs12
    P7B               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    P7C               Digital ID File                                                  application/pkcs7-mime
    P7M               PKCS #7 MIME Message                                             application/pkcs7-mime
    P7R               PKCS #7 Certificates                                             application/x-pkcs7-certreqresp
    P7S               PKCS #7 Signature                                                application/pkcs7-signature
    PBK               Dial-Up Phonebook                                                
    PFM               Type 1 Font file                                                 
    PFX               Personal Information Exchange                                    application/x-pkcs12
    PIF               Shortcut to Program                                              
    PKO               Public Key Security Object                                       application/vnd.ms-pki.pko
    PMA               PMA File                                                         
    PMC               PMC File                                                         
    PML               PML File                                                         
    PMR               PMR File                                                         
    PMW               PMW File                                                         
    PNF               Precompiled Setup Information                                    
    PNG               PNG Image                                                        image/png
    PPI               Microsoft Passport Configuration File                            
    PRF               PICS Rules File                                                  application/pics-rules
    PSW               Password Backup                                                  
    QDS               Directory Query                                                  
    RAT               Rating System File                                               application/rat-file
    RDP               Remote Desktop Connection                                        
    REG               Registration Entries                                             
    RMI               MIDI Sequence                                                    audio/mid
    RNK               Dial-Up Shortcut                                                 
    RTF               RTF File                                                         
    SCF               Windows Explorer Command                                         
    SCP               Text Document                                                    
    SCR               Screen Saver                                                     
    SCT               Windows Script Component                                         text/scriptlet
    SDB               Appfix Package                                                   
    SHB               Shortcut into a document                                         
    SHS               Scrap object                                                     
    SHTML             Firefox Document                                                 text/html
    SND               AU Format Sound                                                  audio/basic
    SPC               PKCS #7 Certificates                                             application/x-pkcs7-certificates
    SST               Microsoft Serialized Certificate Store                           application/vnd.ms-pki.certstore
    STL               Certificate Trust List                                           application/vnd.ms-pki.stl
    SYS               System file                                                      
    THEME             Windows Theme File                                               
    TIF               TIF File                                                         image/tiff
    TIFF              TIFF File                                                        image/tiff
    TTC               TrueType Collection Font file                                    
    TTF               TrueType Font file                                               
    TXT               Text Document                                                    text/plain
    UDL               Microsoft Data Link                                              
    ULS               Internet Location Service                                        text/iuls
    URL               Internet Shortcut                                                
    VBE               VBScript Encoded Script File                                     
    VBS               VBScript Script File                                             
    VCF               vCard File                                                       text/x-vcard
    VXD               Virtual device driver                                            
    WAB               Address Book File                                                
    WAV               Wave Sound                                                       audio/wav
    WAX               Windows Media Audio shortcut                                     audio/x-ms-wax
    WEBPNP            Webpnp                                                           
    WHT               Microsoft NetMeeting Old Whiteboard Document                     
    WM                Windows Media Audio/Video file                                   video/x-ms-wm
    WMA               Windows Media Audio file                                         audio/x-ms-wma
    WMD               Windows Media Player Download Package                            application/x-ms-wmd
    WMDB              Windows Media Library                                            
    WMF               WMF File                                                         
    WMS               Windows Media Player Skin File                                   
    WMV               Windows Media Audio/Video file                                   video/x-ms-wmv
    WMX               Windows Media Audio/Video playlist                               video/x-ms-wmx
    WMZ               Windows Media Player Skin Package                                application/x-ms-wmz
    WPL               Windows Media playlist                                           application/vnd.ms-wpl
    WSC               Windows Script Component                                         text/scriptlet
    WSF               Windows Script File                                              
    WSH               Windows Script Host Settings File                                
    WTX               Text Document                                                    
    WVX               Windows Media Audio/Video playlist                               video/x-ms-wvx
    XHT               Firefox Document                                                 application/xhtml+xml
    XHTML             Firefox Document                                                 application/xhtml+xml
    XML               XML Document                                                     text/xml
    XSL               XSL Stylesheet                                                   text/xml
    ZAP               Software Installation Settings                                   
    ZFSENDTOTARGET    Compressed (zipped) Folder SendTo Target                         
    ZIP               Compressed (zipped) Folder                                       application/x-zip-compressed


--------[ Windows Security ]--------------------------------------------------------------------------------------------

    Operating System Properties:
      OS Name                                           Microsoft Windows Small Business Server 2003, Standard Edition
      OS Service Pack                                   Service Pack 2
      Winlogon Shell                                    Explorer.exe
      System Restore                                    Not Supported

    Data Execution Prevention (DEP, NX, EDB):
      Supported by Operating System                     Yes
      Supported by CPU                                  Yes
      Active (To Protect Applications)                  Yes
      Active (To Protect Drivers)                       Yes


--------[ Windows Update ]----------------------------------------------------------------------------------------------

    (Automatic Update)                                                                Download:Automatic, Install:Notify  
    Hotfix for Windows Server 2003 (KB936598-v2)                                      Update                1/15/2008
    Hotfix for Windows Server 2003 (KB937108-v2)                                      Update                1/15/2008
    Security Update for Windows Server 2003 (KB921503)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB924667-v2)                             Update                1/14/2008
    Security Update for Windows Server 2003 (KB925902)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB926122)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB930178)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB931784)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB932168)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB933729)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB933854)                                QFE                   
    Security Update for Windows Server 2003 (KB933854)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB935839)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB935840)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB936021)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB936782)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB938127)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB941568)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB941569)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB941644)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB942615)                                Update                1/14/2008
    Security Update for Windows Server 2003 (KB942830)                                Update                2/16/2008
    Security Update for Windows Server 2003 (KB942831)                                Update                2/16/2008
    Security Update for Windows Server 2003 (KB943055)                                Update                2/16/2008
    Security Update for Windows Server 2003 (KB943485)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB944533)                                Update                2/16/2008
    Security Update for Windows Server 2003 (KB944653)                                Update                1/15/2008
    Security Update for Windows Server 2003 (KB946026)                                Update                2/16/2008
    This Security Update is for Microsoft .NET Framework 2.0. \n
If you later install a more recent service pack, this Security Update will be uninstalled automatically. \n
For more information, visit http://support.microsoft.com/kb/928365  Update                1/14/2008
    Update for Windows Home Server (KB941914)                                         Update                1/15/2008
    Update for Windows Home Server (KB946146)                                         Update                3/29/2008
    Update for Windows Server 2003 (KB927891)                                         Update                1/14/2008
    Update for Windows Server 2003 (KB937153-v2)                                      Update                1/15/2008
    Update for Windows Server 2003 (KB937253-v2)                                      Update                1/15/2008
    Update for Windows Server 2003 (KB942763)                                         Update                1/14/2008
    Update for Windows Server 2003 (KB942840)                                         Update                1/15/2008
    Update for Windows Server 2003 (KB948496)                                         Update                3/14/2008
    Windows Home Server Activation Component                                          Update                1/15/2008
    Windows Home Server Backup Service                                                Update                1/15/2008
    Windows Home Server Certificate Enrollment (Public Service)                       Update                1/15/2008
    Windows Home Server Certificate Enrollment (Setup module)                         Update                1/15/2008
    Windows Home Server Certificate Enrollment                                        Update                1/15/2008
    Windows Home Server Console                                                       Update                1/15/2008
    Windows Home Server Critical Process Monitor                                      Update                1/15/2008
    Windows Home Server Drive Extender                                                Update                1/15/2008
    Windows Home Server Dynamic DNS Service                                           Update                1/15/2008
    Windows Home Server Event Parser                                                  Update                1/15/2008
    Windows Home Server Notification Service                                          Update                1/15/2008
    Windows Home Server OOBE Setup Module                                             Update                1/15/2008
    Windows Home Server Port Forwarding Service                                       Update                1/15/2008
    Windows Home Server Preserver                                                     Update                1/15/2008
    Windows Home Server Remote Access (Base Package)                                  Update                1/15/2008
    Windows Home Server Remote Access (Public)                                        Update                1/15/2008
    Windows Home Server Remote Access (RWW)                                           Update                1/15/2008
    Windows Home Server SDK                                                           Update                1/15/2008
    Windows Home Server Storage Service                                               Update                1/15/2008
    Windows Home Server Transport Service                                             Update                1/15/2008
    Windows Home Server UPnP and Media Connect Pack                                   Update                1/15/2008


--------[ Firewall ]----------------------------------------------------------------------------------------------------

    Windows Firewall                                 5.2.3790.3959  Enabled


--------[ Regional ]----------------------------------------------------------------------------------------------------

    Time Zone:
      Current Time Zone                                 W. Europe Standard Time
      Current Time Zone Description                     (GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna
      Change To Standard Time                           Last Sunday of October 03:00:00
      Change To Daylight Saving Time                    Last Sunday of March 02:00:00

    Language:
      Language Name (Native)                            English
      Language Name (English)                           English
      Language Name (ISO 639)                           en

    Country/Region:
      Country Name (Native)                             United States
      Country Name (English)                            United States
      Country Name (ISO 3166)                           US
      Country Code                                      1

    Currency:
      Currency Name (Native)                            US Dollar
      Currency Name (English)                           US Dollar
      Currency Symbol (Native)                          $
      Currency Symbol (ISO 4217)                        USD
      Currency Format                                   $123,456,789.00
      Negative Currency Format                          ($123,456,789.00)

    Formatting:
      Time Format                                       HH:mm:ss
      Short Date Format                                 M/d/yyyy
      Long Date Format                                  dddd, MMMM dd, yyyy
      Number Format                                     123,456,789.00
      Negative Number Format                            -123,456,789.00
      List Format                                       first, second, third
      Native Digits                                     0123456789

    Days of Week:
      Native Name for Monday                            Monday / Mon
      Native Name for Tuesday                           Tuesday / Tue
      Native Name for Wednesday                         Wednesday / Wed
      Native Name for Thursday                          Thursday / Thu
      Native Name for Friday                            Friday / Fri
      Native Name for Saturday                          Saturday / Sat
      Native Name for Sunday                            Sunday / Sun

    Months:
      Native Name for January                           January / Jan
      Native Name for February                          February / Feb
      Native Name for March                             March / Mar
      Native Name for April                             April / Apr
      Native Name for May                               May / May
      Native Name for June                              June / Jun
      Native Name for July                              July / Jul
      Native Name for August                            August / Aug
      Native Name for September                         September / Sep
      Native Name for October                           October / Oct
      Native Name for November                          November / Nov
      Native Name for December                          December / Dec

    Miscellaneous:
      Calendar Type                                     Gregorian (localized)
      Default Paper Size                                US Letter
      Measurement System                                Metric


--------[ Environment ]-------------------------------------------------------------------------------------------------

    ALLUSERSPROFILE           C:\Documents and Settings\All Users
    APPDATA                   C:\Documents and Settings\Administrator\Application Data
    CLIENTNAME                BIER
    ClusterLog                C:\WINDOWS\Cluster\cluster.log
    CommonProgramFiles        C:\Program Files\Common Files
    COMPUTERNAME              WEBERSERVER
    ComSpec                   C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK          NO
    HOMEDRIVE                 C:
    HOMEPATH                  \Documents and Settings\Administrator
    LOGONSERVER               \\WEBERSERVER
    NUMBER_OF_PROCESSORS      1
    OS                        Windows_NT
    Path                      C:\Program Files\Tools\;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
    PATHEXT                   .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE    x86
    PROCESSOR_IDENTIFIER      x86 Family 15 Model 127 Stepping 2, AuthenticAMD
    PROCESSOR_LEVEL           15
    PROCESSOR_REVISION        7f02
    ProgramFiles              C:\Program Files
    QLOGS                     C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs
    SESSIONNAME               RDP-Tcp#1
    SystemDrive               C:
    SystemRoot                C:\WINDOWS
    TEMP                      C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1
    TMP                       C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1
    USERDOMAIN                WEBERSERVER
    USERNAME                  Administrator
    USERPROFILE               C:\Documents and Settings\Administrator
    windir                    C:\WINDOWS


--------[ Control Panel ]-----------------------------------------------------------------------------------------------

    Accessibility Options                     Adjust your computer settings for vision, hearing, and mobility.
    Add Hardware                              Installs and troubleshoots hardware
    Add or Remove Programs                    Install or remove programs and Windows components.
    Administrative Tools                      Configure administrative settings for your computer.
    Automatic Updates                         Set up Windows to automatically deliver important updates
    Date and Time                             Set the date, time, and time zone for your computer.
    Display                                   Change the appearance of your desktop, such as the background, screen saver, colors, font sizes, and screen resolution.
    Folder Options                            Customize the display of files and folders, change file associations, and make network files available offline.
    Fonts                                     Add, change, and manage fonts on your computer.
    Game Controllers                          Add, remove, and configure game controller hardware such as joysticks and gamepads.
    Internet Options                          Configure your Internet display and connection settings.
    Keyboard                                  Customize your keyboard settings, such as the cursor blink rate and the character repeat rate.
    Licensing                                 Changes licensing options
    Mouse                                     Customize your mouse settings, such as the button configuration, double-click speed, mouse pointers, and motion speed.
    Network Connections                       Connects to other computers, networks, and the Internet.
    Phone and Modem Options                   Configure your telephone dialing rules and modem settings.
    Portable Media Devices                    View the portable media devices connected to your computer.
    Power Options                             Configure energy-saving settings for your computer.
    Printers and Faxes                        Shows installed printers and fax printers and helps you add new ones.
    Regional and Language Options             Customize settings for the display of languages, numbers, times, and dates.
    Scanners and Cameras                      Add, remove, and configure scanners and cameras.
    Scheduled Tasks                           Schedule computer tasks to run automatically.
    Sounds and Audio Devices                  Change the sound scheme for your computer, or configure the settings for your speakers and recording devices.
    Speech                                    Change settings for text-to-speech and for speech recognition (if installed).
    Stored User Names and Passwords           Manages stored credentials for network servers.
    System                                    See information about your computer system, and change settings for hardware, performance, and automatic updates.
    Taskbar and Start Menu                    Customize the Start Menu and the taskbar, such as the types of items to be displayed and how they should appear.
    Windows Firewall                          Configure the Windows Firewall


--------[ Recycle Bin ]-------------------------------------------------------------------------------------------------

    C:        83 MB        80    2 %  Enabled
    D:      3756 MB        11    2 %  Enabled


--------[ System Files ]------------------------------------------------------------------------------------------------

  [ autoexec.nt ]

    @echo off
    
    REM AUTOEXEC.BAT is not used to initialize the MS-DOS environment.
    REM AUTOEXEC.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    
    REM Install CD ROM extensions
    lh %SystemRoot%\system32\mscdexnt.exe
    
    REM Install network redirector (load before dosx.exe)
    lh %SystemRoot%\system32\redir
    
    REM Install DPMI support
    lh %SystemRoot%\system32\dosx
    
    REM The following line enables Sound Blaster 2.0 support on NTVDM.
    REM The command for setting the BLASTER environment is as follows:
    REM    SET BLASTER=A220 I5 D1 P330
    REM    where:
    REM        A    specifies the sound blaster's base I/O port
    REM        I    specifies the interrupt request line
    REM        D    specifies the 8-bit DMA channel
    REM        P    specifies the MPU-401 base I/O port
    REM        T    specifies the type of sound blaster card
    REM                 1 - Sound Blaster 1.5
    REM                 2 - Sound Blaster Pro I
    REM                 3 - Sound Blaster 2.0
    REM                 4 - Sound Blaster Pro II
    REM                 6 - SOund Blaster 16/AWE 32/32/64
    REM
    REM    The default value is A220 I5 D1 T3 and P330.  If any of the switches is
    REM    left unspecified, the default value will be used. (NOTE, since all the
    REM    ports are virtualized, the information provided here does not have to
    REM    match the real hardware setting.)  NTVDM supports Sound Blaster 2.0 only.
    REM    The T switch must be set to 3, if specified.
    SET BLASTER=A220 I5 D1 P330 T3
    
    REM To disable the sound blaster 2.0 support on NTVDM, specify an invalid
    REM SB base I/O port address.  For example:
    REM    SET BLASTER=A0

  [ config.nt ]

    REM Windows MS-DOS Startup File
    REM
    REM CONFIG.SYS vs CONFIG.NT
    REM CONFIG.SYS is not used to initialize the MS-DOS environment.
    REM CONFIG.NT is used to initialize the MS-DOS environment unless a
    REM different startup file is specified in an application's PIF.
    REM
    REM ECHOCONFIG
    REM By default, no information is displayed when the MS-DOS environment
    REM is initialized. To display CONFIG.NT/AUTOEXEC.NT information, add
    REM the command echoconfig to CONFIG.NT or other startup file.
    REM
    REM NTCMDPROMPT
    REM When you return to the command prompt from a TSR or while running an
    REM MS-DOS-based application, Windows runs COMMAND.COM. This allows the
    REM TSR to remain active. To run CMD.EXE, the Windows command prompt,
    REM rather than COMMAND.COM, add the command ntcmdprompt to CONFIG.NT or
    REM other startup file.
    REM
    REM DOSONLY
    REM By default, you can start any type of application when running
    REM COMMAND.COM. If you start an application other than an MS-DOS-based
    REM application, any running TSR may be disrupted. To ensure that only
    REM MS-DOS-based applications can be started, add the command dosonly to
    REM CONFIG.NT or other startup file.
    REM
    REM EMM
    REM You can use EMM command line to configure EMM(Expanded Memory Manager).
    REM The syntax is:
    REM
    REM EMM = [A=AltRegSets] [B=BaseSegment] [RAM]
    REM
    REM     AltRegSets
    REM         specifies the total Alternative Mapping Register Sets you
    REM         want the system to support. 1 <= AltRegSets <= 255. The
    REM         default value is 8.
    REM     BaseSegment
    REM         specifies the starting segment address in the Dos conventional
    REM         memory you want the system to allocate for EMM page frames.
    REM         The value must be given in Hexdecimal.
    REM         0x1000 <= BaseSegment <= 0x4000. The value is rounded down to
    REM         16KB boundary. The default value is 0x4000
    REM     RAM
    REM         specifies that the system should only allocate 64Kb address
    REM         space from the Upper Memory Block(UMB) area for EMM page frames
    REM         and leave the rests(if available) to be used by DOS to support
    REM         loadhigh and devicehigh commands. The system, by default, would
    REM         allocate all possible and available UMB for page frames.
    REM
    REM     The EMM size is determined by pif file(either the one associated
    REM     with your application or _default.pif). If the size from PIF file
    REM     is zero, EMM will be disabled and the EMM line will be ignored.
    REM
    dos=high, umb
    device=%SystemRoot%\system32\himem.sys
    files=40

  [ msdos.sys ]


  [ boot.ini ]

    [boot loader]
    timeout=30
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows Server 2003 for Small Business Server" /noexecute=optout /fastdetect /usepmtimer

  [ system.ini ]

    ; for 16-bit app support
    
    [drivers]
    wave=mmdrv.dll
    timer=timer.drv
    
    [mci]
    [driver32]
    [386enh]
    woafont=dosapp.FON
    EGA80WOA.FON=EGA80WOA.FON
    EGA40WOA.FON=EGA40WOA.FON
    CGA80WOA.FON=CGA80WOA.FON
    CGA40WOA.FON=CGA40WOA.FON

  [ win.ini ]

    ; for 16-bit app support
    [fonts]
    [extensions]
    [mci extensions]
    [files]
    [Mail]
    MAPI=1
    [MCI Extensions.BAK]
    aif=MPEGVideo
    aifc=MPEGVideo
    aiff=MPEGVideo
    asf=MPEGVideo
    asx=MPEGVideo
    au=MPEGVideo
    m1v=MPEGVideo
    m3u=MPEGVideo
    mp2=MPEGVideo
    mp2v=MPEGVideo
    mp3=MPEGVideo
    mpa=MPEGVideo
    mpe=MPEGVideo
    mpeg=MPEGVideo
    mpg=MPEGVideo
    mpv2=MPEGVideo
    snd=MPEGVideo
    wax=MPEGVideo
    wm=MPEGVideo
    wma=MPEGVideo
    wmv=MPEGVideo
    wmx=MPEGVideo
    wpl=MPEGVideo
    wvx=MPEGVideo

  [ hosts ]

    

  [ lmhosts.sam ]

    
    
    
    


--------[ System Folders ]----------------------------------------------------------------------------------------------

    Administrative Tools         C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
    AppData                      C:\Documents and Settings\Administrator\Application Data
    Cache                        C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
    CD Burning                   C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\CD Burning
    Common Administrative Tools  C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
    Common AppData               C:\Documents and Settings\All Users\Application Data
    Common Desktop               C:\Documents and Settings\All Users\Desktop
    Common Documents             C:\Documents and Settings\All Users\Documents
    Common Favorites             C:\Documents and Settings\All Users\Favorites
    Common Programs              C:\Documents and Settings\All Users\Start Menu\Programs
    Common Start Menu            C:\Documents and Settings\All Users\Start Menu
    Common Startup               C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    Common Templates             C:\Documents and Settings\All Users\Templates
    CommonMusic                  C:\Documents and Settings\All Users\Documents\My Music
    CommonVideo                  C:\Documents and Settings\All Users\Documents\My Videos
    Cookies                      C:\Documents and Settings\Administrator\Cookies
    Desktop                      C:\Documents and Settings\Administrator\Desktop
    Device                       C:\WINDOWS\inf
    Favorites                    C:\Documents and Settings\Administrator\Favorites
    Fonts                        C:\WINDOWS\Fonts
    History                      C:\Documents and Settings\Administrator\Local Settings\History
    Local AppData                C:\Documents and Settings\Administrator\Local Settings\Application Data
    Local Settings               C:\Documents and Settings\Administrator\Local Settings
    Media                        C:\WINDOWS\Media
    My Music                     C:\Documents and Settings\Administrator\My Documents\My Music
    My Pictures                  C:\Documents and Settings\Administrator\My Documents\My Pictures
    My Video                     C:\Documents and Settings\Administrator\My Documents\My Videos
    NetHood                      C:\Documents and Settings\Administrator\NetHood
    Personal                     C:\Documents and Settings\Administrator\My Documents
    PrintHood                    C:\Documents and Settings\Administrator\PrintHood
    Program Files                C:\Program Files
    Programs                     C:\Documents and Settings\Administrator\Start Menu\Programs
    Recent                       C:\Documents and Settings\Administrator\Recent
    SendTo                       C:\Documents and Settings\Administrator\SendTo
    Start Menu                   C:\Documents and Settings\Administrator\Start Menu
    Startup                      C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
    System                       C:\WINDOWS\system32
    Temp                         C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\1\
    Templates                    C:\Documents and Settings\Administrator\Templates
    Wallpaper                    C:\WINDOWS\Web\Wallpaper
    Windows                      C:\WINDOWS


--------[ Event Logs ]--------------------------------------------------------------------------------------------------

    Application  Information     2          2008-01-14 12:46:57                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-14 12:46:58                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     1          2008-01-14 20:32:33                                  ESENT                           100: svchost (680) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-14 21:07:13                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-14 21:10:47                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:10:47                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-14 21:11:49                                  ESENT                           101: svchost (828) The database engine stopped.  
    Application  Information     None       2008-01-14 21:16:34                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-14 21:16:34                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-14 21:16:45                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-14 21:20:38                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:20:38                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-14 21:48:32                                  ASP.NET 1.1.4322.0              1017: Start registering ASP.NET (version 1.1.4322.0)  
    Application  Information     None       2008-01-14 21:48:42                                  LoadPerf                        1000: Performance counters for the ASP.NET_1.1.4322 (ASP.NET_1.1.4322) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-14 21:48:44                                  ASP.NET 1.1.4322.0              1023: Restarting W3SVC  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1001: Performance counters for the ContentIndex (ContentIndex) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1001: Performance counters for the ContentFilter (ContentFilter) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1001: Performance counters for the ISAPISearch (ISAPISearch) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1000: Performance counters for the ContentIndex (ContentIndex) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1000: Performance counters for the ContentFilter (ContentFilter) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-14 21:48:50                                  LoadPerf                        1000: Performance counters for the ISAPISearch (ISAPISearch) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-14 21:48:50                                  ASP.NET 1.1.4322.0              1025: Finish restarting W3SVC  
    Application  Information     1          2008-01-14 21:48:50                                  ASP.NET 1.1.4322.0              1019: Finish registering ASP.NET (version 1.1.4322.0). Detailed registration logs can be found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\4\ASPNETSetup.log  
    Application  Information     None       2008-01-14 21:50:19                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-14 21:50:19                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-14 21:50:30                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-14 21:53:09                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-14 21:53:09                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-14 21:53:20                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-14 21:57:13                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 21:57:13                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-14 22:49:14  Administrator                   MsiInstaller                    11707: Product: Windows Home Server - uTorrent -- Installation completed successfully.  
    Application  Information     None       2008-01-14 23:04:54  Administrator                   MsiInstaller                    11728: Product: Windows Home Server - uTorrent -- Configuration completed successfully.  
    Application  Information     None       2008-01-14 23:10:48  Administrator                   MsiInstaller                    11724: Product: Windows Home Server - uTorrent -- Removal completed successfully.  
    Application  Information     2          2008-01-14 23:54:44                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-14 23:54:45                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-14 23:54:55                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-14 23:58:49                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-14 23:58:49                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 00:47:45                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 00:47:48                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 00:47:50                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 00:48:31                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 00:48:31                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Error           None       2008-01-15 00:49:07                                  VDS Basic Provider 1.0          
    Application  Error           None       2008-01-15 00:49:07                                  VDS Basic Provider 1.0          
    Application  Error           None       2008-01-15 00:49:07                                  VDS Basic Provider 1.0          
    Application  Information     None       2008-01-15 00:51:30                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 00:51:30                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:35:43                                  LoadPerf                        1000: Performance counters for the IPSec (IPSEC driver) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:36:11                                  LoadPerf                        1000: Performance counters for the RemoteAccess (Routing and Remote Access) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:36:30                                  LoadPerf                        1000: Performance counters for the TermService (Terminal Services) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:36:33                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:36:34                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 04:36:34                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-15 04:36:39  SYSTEM                          WinMgmt                         63: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  
    Application  Warning         None       2008-01-15 04:36:41  SYSTEM                          WinMgmt                         63: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  
    Application  Warning         None       2008-01-15 04:36:41  SYSTEM                          WinMgmt                         63: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  
    Application  Information     None       2008-01-15 04:36:48                                  LoadPerf                        1000: Performance counters for the MSDTC (MSDTC) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:36:49                                  LoadPerf                        1002: Performance counters for the MSDTC (Distributed Transaction Coordinator) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     1          2008-01-15 04:36:51                                  MSDTC                           4104: The Microsoft Distributed Transaction Coordinator service was successfully installed.
    Application  Information     2          2008-01-15 04:36:54                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 04:37:00                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-15 04:37:11                                  LoadPerf                        1000: Performance counters for the inetinfo (inetinfo) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:37:17                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-15 04:37:17                                  COM+                            781: The COM+ sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\COM3\Eventlog.  
    Application  Information     113        2008-01-15 04:37:17                                  COM+                            4156: String message: First attemp to CoCreateInstance(CLSID_ComSystemAppEventData) failed!.
    Application  Information     113        2008-01-15 04:37:17                                  COM+                            4156: String message: Remove old EventClass(CLSID_ComSystemAppEventData) from event system!..
    Application  Information     113        2008-01-15 04:37:17                                  COM+                            4156: String message: Added EventClass(CLSID_ComSystemAppEventData) to event system!..
    Application  Information     113        2008-01-15 04:37:17                                  COM+                            4156: String message: RegisterComSystemAppEventData() succeeded!  Will re-try CoCreateInstance(CLSID_ComSystemAppEventData).
    Application  Information     None       2008-01-15 04:37:33                                  LoadPerf                        1000: Performance counters for the .NET CLR Data (.NET CLR Data) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:37:33                                  LoadPerf                        1000: Performance counters for the .NET CLR Networking (.NET CLR Networking) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:37:48                                  LoadPerf                        1000: Performance counters for the .NETFramework (.NETFramework) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:37:50                                  LoadPerf                        1000: Performance counters for the W3SVC (World Wide Web Publishing Service) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:37:50                                  LoadPerf                        1000: Performance counters for the ASP (ASP) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 04:38:00                                  ASP.NET 1.1.4322.0              1017: Start registering ASP.NET (version 1.1.4322.0)  
    Application  Information     None       2008-01-15 04:38:11                                  LoadPerf                        1000: Performance counters for the ASP.NET_1.1.4322 (ASP.NET_1.1.4322) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:38:15                                  LoadPerf                        1000: Performance counters for the ASP.NET (ASP.NET) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 04:38:16                                  ASP.NET 1.1.4322.0              1023: Restarting W3SVC  
    Application  Information     1          2008-01-15 04:38:16                                  ASP.NET 1.1.4322.0              1025: Finish restarting W3SVC  
    Application  Information     1          2008-01-15 04:38:16                                  ASP.NET 1.1.4322.0              1019: Finish registering ASP.NET (version 1.1.4322.0). Detailed registration logs can be found in C:\Documents and Settings\Default User\ASPNETSetup.log  
    Application  Information     None       2008-01-15 04:38:17                                  LoadPerf                        1000: Performance counters for the ContentIndex (ContentIndex) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:38:17                                  LoadPerf                        1000: Performance counters for the ContentFilter (ContentFilter) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:38:17                                  LoadPerf                        1000: Performance counters for the ISAPISearch (ISAPISearch) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:39:01                                  LoadPerf                        1002: Performance counters for the IPSec (IPSEC driver) service are already in Performance  Registry, no need to re-install again.  
    Application  Warning         None       2008-01-15 04:39:27  SYSTEM                          WinMgmt                         5603: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.        
    Application  Warning         None       2008-01-15 04:39:27  SYSTEM                          WinMgmt                         5603: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property.  This provider will be run using the LocalSystem account.  This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.  Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.        
    Application  Information     1          2008-01-15 04:39:33                                  PassportManager                 5000: Passport Manager process started successfully.  
    Application  Information     1          2008-01-15 04:39:33                                  PassportManager                 5011: A new key has been installed.  
    Application  Information     None       2008-01-15 04:39:48                                  WmdmPmSN                        100: The WmdmPmSN service was installed.  
    Application  Information     None       2008-01-15 04:39:56                                  TrustMonitor                    1: The TrustMon MOF file was successfully compiled into the WMI repository.  
    Application  Information     None       2008-01-15 04:39:56                                  DSReplicationProvider           1: The DS WMI Replication provider (Replprov) MOF file was successfully compiled into the WMI repository.  
    Application  Information     None       2008-01-15 04:40:37                                  SceCli                          1500: Security configuration was backed up to C:\WINDOWS\security\templates\setup security.inf.  
    Application  Information     1          2008-01-15 04:42:44                                  PassportManager                 5001: Passport Manager process was stopped.  
    Application  Information     2          2008-01-15 04:43:54                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 04:43:55                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     1          2008-01-15 04:43:57                                  ESENT                           100: svchost (892) The database engine 5.02.3790.3959 started.  
    Application  Warning         None       2008-01-15 04:44:03                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 30 days.    
    Application  Information     None       2008-01-15 04:47:40                                  Winlogon                        1001: Checking file system on C:  The type of the file system is NTFS.  Volume label is SYS.      One of your disks needs to be checked for consistency. You  may cancel the disk check, but it is strongly recommended  that you continue.  Windows will now check the disk.                           Cleaning up minor inconsistencies on the drive.  Cleaning up 53 unused index entries from index $SII of file 0x9.  Cleaning up 53 unused index entries from index $SDH of file 0x9.  Cleaning up 53 unused security descriptors.  The upcase file content is incorrect.  Correcting errors in the uppercase file.  Windows has made corrections to the file system.      20972825 KB total disk space.     3339416 KB in 10363 files.        2624 KB in 929 indexes.           0 KB in bad sectors.       80521 KB in use by the system.       65536 KB occupied by the log file.    17550264 KB available on disk.          4096 bytes in each allocation unit.     5243206 total allocation units on disk.     4387566 allocation units available on disk.    Internal Info:  30 36 00 00 27 2c 00 00 0a 33 00 00 00 00 00 00  06..',...3......  33 00 00 00 00 00 00 00 d4 00 00 00 00 00 00 00  3...............  3a d3 74 00 00 00 00 00 70 ec fd 04 00 00 00 00  :.t.....p.......  42 82 a4 00 00 00 00 00 00 00 00 00 00 00 00 00  B...............  00 00 00 00 00 00 00 00 90 b6 e3 0c 00 00 00 00  ................  99 9e 36 00 00 00 00 00 ff ff ff ff 05 00 00 00  ..6.............  7b 28 00 00 00 00 00 00 00 60 d2 cb 00 00 00 00  {(.......`......    Windows has finished checking your disk.  Please wait while your computer restarts.    
    Application  Information     None       2008-01-15 04:47:41                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 04:47:41                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-15 04:47:55                                  ESENT                           100: svchost (824) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-15 04:49:11                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 04:49:11                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-15 04:49:15                                  ESENT                           100: svchost (824) The database engine 5.02.3790.3959 started.  
    Application  Information     1          2008-01-15 04:49:59                                  ASP.NET 2.0.50727.0             1017: Start registering ASP.NET (version 2.0.50727.0) (internal flag: 0x0000040e)  
    Application  Information     None       2008-01-15 04:50:08                                  LoadPerf                        1000: Performance counters for the aspnet_state (ASP.NET State Service) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:50:18                                  LoadPerf                        1000: Performance counters for the ASP.NET_2.0.50727 (ASP.NET_2.0.50727) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:50:18                                  LoadPerf                        1001: Performance counters for the ASP.NET (ASP.NET) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 04:50:27                                  LoadPerf                        1000: Performance counters for the ASP.NET (ASP.NET) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:50:27                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 04:50:27                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 04:50:28                                  ASP.NET 2.0.50727.0             1023: Restarting W3SVC  
    Application  Information     1          2008-01-15 04:50:28                                  ASP.NET 2.0.50727.0             1025: Finish restarting W3SVC  
    Application  Information     1          2008-01-15 04:50:28                                  ASP.NET 2.0.50727.0             1019: Finish registering ASP.NET (version 2.0.50727.0). Detailed registration logs can be found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ASPNETSetup_00000.log  
    Application  Information     None       2008-01-15 04:51:25                                  LoadPerf                        1002: Performance counters for the .NET CLR Networking (.NET CLR Networking) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 04:51:25                                  LoadPerf                        1000: Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:51:26                                  LoadPerf                        1000: Performance counters for the .NET Data Provider for SqlServer (.NET Data Provider for SqlServer) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:51:26                                  LoadPerf                        1002: Performance counters for the .NET CLR Data (.NET CLR Data) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 04:51:26                                  LoadPerf                        1002: Performance counters for the .NETFramework (.NETFramework) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 04:51:27  Administrator                   MsiInstaller                    11707: Product: Microsoft .NET Framework 2.0 -- Installation completed successfully.  
    Application  Information     None       2008-01-15 04:51:53                                  LoadPerf                        1000: Performance counters for the wsearchidxpi (wsearchidxpi) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:51:54                                  LoadPerf                        1000: Performance counters for the UGTHRSVC (UGTHRSVC) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 04:51:54                                  LoadPerf                        1000: Performance counters for the UGatherer (UGatherer) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 04:51:59                                  Windows Search Service          
    Application  Information     1          2008-01-15 04:52:48                                  Windows Search Service          
    Application  Information     1          2008-01-15 04:52:49                                  Windows Search Service          
    Application  Information     3          2008-01-15 04:52:55                                  Windows Search Service          
    Application  Information     None       2008-01-15 04:53:22                                  DEfilter installer              0: DEfilter install started  
    Application  Information     None       2008-01-15 04:53:22                                  DEfilter installer              0: fltinst, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 - copying filter to C:\WINDOWS\system32\DRIVERS\DEfilter.sys  
    Application  Information     None       2008-01-15 04:53:23                                  DEfilter installer              0: fltinst, Version=6.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 -  Installing DEfilter  
    Application  Information     None       2008-01-15 04:53:23                                  DEfilter installer              0: Filter driver install ending. SuccessCode = 0  
    Application  Information     None       2008-01-15 04:53:23                                  DEfilter installer              0: DEfilter install ended. SuccessCode = 0  
    Application  Warning         None       2008-01-15 04:53:30                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-15 04:53:31                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 04:55:04                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         3          2008-01-15 04:55:58                                  Windows Search Service          
    Application  Information     1          2008-01-15 04:56:01                                  Windows Search Service          
    Application  Information     1          2008-01-15 04:56:06                                  Windows Search Service          
    Application  Information     None       2008-01-15 04:57:38                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 04:57:38                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-15 04:57:45                                  Windows Search Service          
    Application  Information     3          2008-01-15 04:57:49                                  Windows Search Service          
    Application  Information     None       2008-01-15 04:58:00                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     1          2008-01-15 04:58:02                                  ESENT                           100: svchost (836) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-15 05:01:40                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:01:40                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 05:03:12                                  Windows Search Service          
    Application  Information     None       2008-01-15 05:03:14                                  LoadPerf                        1001: Performance counters for the UGatherer (UGatherer) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:03:14                                  LoadPerf                        1001: Performance counters for the UGTHRSVC (UGTHRSVC) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:03:14                                  LoadPerf                        1001: Performance counters for the wsearchidxpi (wsearchidxpi) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     2          2008-01-15 05:04:54                                  ASP.NET 1.1.4322.0              1073: Start unregistering ASP.NET (version 1.1.4322.0)    
    Application  Information     None       2008-01-15 05:04:55                                  LoadPerf                        1001: Performance counters for the ASP.NET_1.1.4322 (ASP.NET_1.1.4322) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:04:55                                  LoadPerf                        1001: Performance counters for the ASP.NET (ASP.NET) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     2          2008-01-15 05:04:55                                  ASP.NET 1.1.4322.0              1073: The current version at the IIS root is 2.0.50727.0.    
    Application  Information     None       2008-01-15 05:05:05                                  LoadPerf                        1000: Performance counters for the ASP.NET (ASP.NET) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     2          2008-01-15 05:05:06                                  ASP.NET 1.1.4322.0              1073: Restarting W3SVC    
    Application  Information     2          2008-01-15 05:05:09                                  ASP.NET 1.1.4322.0              1073: Finish restarting W3SVC    
    Application  Information     2          2008-01-15 05:05:09                                  ASP.NET 1.1.4322.0              1073: Finish unregistering ASP.NET (version 1.1.4322.0). Detailed unregistration logs can be found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ASPNETSetup.log    
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1001: Performance counters for the ContentIndex (ContentIndex) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1001: Performance counters for the ContentFilter (ContentFilter) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1001: Performance counters for the ISAPISearch (ISAPISearch) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1000: Performance counters for the ContentIndex (ContentIndex) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1000: Performance counters for the ContentFilter (ContentFilter) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 05:05:13                                  LoadPerf                        1000: Performance counters for the ISAPISearch (ISAPISearch) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-15 05:06:57                                  WinMgmt                         47: WMI ADAP was unable to retrieve data from the PerfLib subkey: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ASP.NET, error code: 127  
    Application  Warning         None       2008-01-15 05:06:57                                  WinMgmt                         33: WMI ADAP was unable to load the ASP.NET performance library because it threw an exception: 0x0  
    Application  Information     1          2008-01-15 05:08:18                                  ESENT                           101: svchost (836) The database engine stopped.  
    Application  Information     None       2008-01-15 05:22:18                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 05:22:18                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-15 05:22:22                                  ESENT                           100: svchost (844) The database engine 5.02.3790.3959 started.  
    Application  Error           None       2008-01-15 05:22:30                                  Perflib                         1005: Unable to locate the open procedure "?? " in DLL "C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_isapi.dll" for  the "ASP.NET" service. Performance data for this service will not be  available. The Error Status is the first DWORD in the attached  data.  
    Application  Error           None       2008-01-15 05:22:30                                  Perflib                         1017: Performance counter data collection from the "ASP.NET" service has been disabled  due to one or more errors generated by the performance counter library for that  service. The error(s) that forced this action have been written to the application  event log. The error(s) should be corrected before the performance counters  for this service are enabled again.  
    Application  Information     None       2008-01-15 05:22:31                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 05:26:20                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:26:20                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 05:27:44                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Accessibility, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:44                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: AspNetMMCExt, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:44                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Accessibility, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:45                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe   
    Application  Information     None       2008-01-15 05:27:45                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: CustomMarshalers, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:45                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: AspNetMMCExt, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:45                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\dfsvc.exe   
    Application  Information     None       2008-01-15 05:27:46                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Microsoft.Build.Engine, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:46                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: CustomMarshalers, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:47                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Microsoft.Build.Framework, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:47                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Microsoft.Build.Tasks, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:47                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Engine, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:47                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Framework, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:49                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Microsoft.Build.Utilities, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:49                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: Microsoft.VisualBasic, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:49                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Tasks, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:49                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.Build.Utilities, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:51                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:51                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: Microsoft.VisualBasic, Version=8.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:52                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Deployment, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:52                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Configuration, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:53                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.DirectoryServices, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:53                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Deployment, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:54                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:54                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.EnterpriseServices, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:54                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.DirectoryServices, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:54                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.DirectoryServices.Protocols, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:55                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Security, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:55                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.EnterpriseServices, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:56                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Transactions, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089   
    Application  Unknown         None       2008-01-15 05:27:56                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Security, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:27:57                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:27:57                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Transactions, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089   
    Application  Information     1          2008-01-15 05:28:05                                  ESENT                           101: svchost (844) The database engine stopped.  
    Application  Unknown         None       2008-01-15 05:28:08                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:28:09                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Web.Mobile, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:28:11                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Web.RegularExpressions, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:28:11                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Web.Mobile, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:28:12                                  .NET Runtime Optimization Service  1100: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Began compiling: System.Web.Services, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Unknown         None       2008-01-15 05:28:12                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Web.RegularExpressions, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:28:13                                  .NET Runtime Optimization Service  1104: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Completed all work. Shutting down.   
    Application  Unknown         None       2008-01-15 05:28:13                                  .NET Runtime Optimization Service  1102: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Succesfully compiled: System.Web.Services, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a   
    Application  Information     None       2008-01-15 05:36:20                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 05:36:20                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 05:36:26                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 05:37:51                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 05:37:51                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 05:37:57                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 05:41:52                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 05:41:52                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 06:00:50                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-15 06:01:13                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-15 06:04:52  Administrator                   MsiInstaller                    1025: Product: Microsoft .NET Framework 2.0. The file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Aspnet_perf.dll is being held in use by the following process Name: demigrator , Id 2404.  
    Application  Information     None       2008-01-15 06:04:52  Administrator                   MsiInstaller                    1025: Product: Microsoft .NET Framework 2.0. The file C:\WINDOWS\system32\mscoree.dll is being held in use by the following process Name: demigrator , Id 2404.  
    Application  Information     None       2008-01-15 06:04:52  Administrator                   MsiInstaller                    1025: Product: Microsoft .NET Framework 2.0. The file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll is being held in use by the following process Name: demigrator , Id 2404.  
    Application  Information     None       2008-01-15 06:04:55  Administrator                   MsiInstaller                    1025: Product: Microsoft .NET Framework 2.0. The file C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll is being held in use by the following process Name: demigrator , Id 2404.  
    Application  Information     1          2008-01-15 06:05:15                                  ASP.NET 2.0.50727.0             1017: Start registering ASP.NET (version 2.0.50727.0) (internal flag: 0x0000040e)  
    Application  Information     None       2008-01-15 06:05:16                                  LoadPerf                        1001: Performance counters for the ASP.NET_2.0.50727 (ASP.NET_2.0.50727) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 06:05:24                                  LoadPerf                        1002: Performance counters for the aspnet_state (ASP.NET State Service) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 06:05:34                                  LoadPerf                        1000: Performance counters for the ASP.NET_2.0.50727 (ASP.NET_2.0.50727) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 06:05:34                                  LoadPerf                        1001: Performance counters for the ASP.NET (ASP.NET) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 06:05:43                                  LoadPerf                        1000: Performance counters for the ASP.NET (ASP.NET) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 06:05:44                                  ASP.NET 2.0.50727.0             1023: Restarting W3SVC  
    Application  Information     1          2008-01-15 06:05:45                                  ASP.NET 2.0.50727.0             1025: Finish restarting W3SVC  
    Application  Information     1          2008-01-15 06:05:45                                  ASP.NET 2.0.50727.0             1019: Finish registering ASP.NET (version 2.0.50727.0). Detailed registration logs can be found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ASPNETSetup_00001.log  
    Application  Information     None       2008-01-15 06:05:52                                  LoadPerf                        1002: Performance counters for the .NET Data Provider for Oracle (.NET Data Provider for Oracle) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 06:05:53                                  LoadPerf                        1002: Performance counters for the .NET Data Provider for SqlServer (.NET Data Provider for SqlServer) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 06:05:53                                  LoadPerf                        1002: Performance counters for the .NET CLR Networking (.NET CLR Networking) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 06:05:53                                  LoadPerf                        1002: Performance counters for the .NET CLR Data (.NET CLR Data) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     None       2008-01-15 06:05:53                                  LoadPerf                        1002: Performance counters for the .NETFramework (.NETFramework) service are already in Performance  Registry, no need to re-install again.  
    Application  Information     2          2008-01-15 06:09:12                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 06:09:13                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     1          2008-01-15 06:09:17                                  ESENT                           100: svchost (828) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-15 18:01:06                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-15 18:01:29                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     2          2008-01-15 18:37:19                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-15 18:37:20                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-15 18:37:30                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 18:41:34                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 18:41:34                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-15 20:05:54                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-15 20:05:54                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-15 20:06:00                                  ESENT                           100: svchost (844) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-15 20:06:08                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-15 20:10:01                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-15 20:10:01                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     1          2008-01-15 20:11:47                                  ESENT                           101: svchost (844) The database engine stopped.  
    Application  Information     None       2008-01-15 20:31:57  Administrator                   MsiInstaller                    11707: Product: Windows Home Server - uTorrent -- Installation completed successfully.  
    Application  Information     None       2008-01-16 00:00:36                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-16 00:04:26                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-16 00:05:36                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-16 12:00:49                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-16 12:04:42                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-16 12:05:45                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 00:00:49                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 00:04:39                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 00:05:35                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 06:00:39                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 06:04:32                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 06:05:11                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 18:00:38                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 18:05:03                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-17 18:05:45                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Warning         None       2008-01-17 18:28:30                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 14 days.    
    Application  Information     None       2008-01-17 18:36:21                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-17 18:36:21                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Warning         None       2008-01-17 18:36:34                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-17 18:36:35                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-17 18:40:26                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-17 18:40:26                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-19 11:46:59                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-19 11:46:59                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-19 11:47:13                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         None       2008-01-19 11:47:13                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-19 11:47:16                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 11:47:18                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-19 11:48:08                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 11:48:08                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-19 11:51:03                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 11:51:03                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-19 11:51:30                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 13 days.    
    Application  Information     None       2008-01-19 11:56:57  Administrator                   MsiInstaller                    11707: Product: Windows Resource Kit Tools -- Installation operation completed successfully.  
    Application  Information     None       2008-01-19 12:13:45                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-19 12:16:09                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-19 12:17:31                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-19 12:25:27                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-19 12:25:27                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-19 12:25:46                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-19 12:28:52  Administrator                   MsiInstaller                    11724: Product: Windows Home Server - uTorrent -- Removal completed successfully.  
    Application  Information     None       2008-01-19 12:29:07  Administrator                   MsiInstaller                    11707: Product: Windows Home Server - uTorrent -- Installation completed successfully.  
    Application  Information     None       2008-01-19 12:29:35                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 12:29:36                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-19 13:24:47                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-19 13:24:47                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-19 13:25:10                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-19 13:28:54                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 13:28:54                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-19 19:34:30  Administrator                   MsiInstaller                    11707: Product: Client PC Information AddIn -- Installation completed successfully.  
    Application  Information     None       2008-01-19 19:35:29                                  Client Info                     0: The process cannot access the file 'D:\shares\software\ClientInfo\WEBERSERVER.xml' because it is being used by another process.    at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)     at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy)     at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share)     at System.Xml.XmlDocument.Save(String filename)     at Microsoft.HomeServer.HomeServerConsoleTab.ClientInfo.HomeServerTabExtender.QueryServer()  
    Application  Information     None       2008-01-19 19:50:19                                  Client Info                     0: The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)  
    Application  Information     None       2008-01-19 19:50:42                                  Client Info                     0: The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)  
    Application  Information     None       2008-01-19 19:50:46                                  Client Info                     0: The RPC server is unavailable. (Exception from HRESULT: 0x800706BA)  
    Application  Information     None       2008-01-19 19:54:24                                  Client Info                     0: Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))  
    Application  Information     None       2008-01-19 19:54:27                                  Client Info                     0: Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))  
    Application  Information     2          2008-01-19 20:00:38                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-19 20:00:39                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-19 20:01:02                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-19 20:04:44                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-19 20:04:45                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-20 00:04:40                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 00:05:31                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 00:06:11                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Error           None       2008-01-20 01:10:46                                  VSS                             12293: Volume Shadow Copy Service error: Error calling a routine on the Shadow Copy Provider {b5946137-7b9f-4925-af80-51abd60b20d5}. Routine details IVssSnapshotProvider::SetContext [hr = 0x80004002].  
    Application  Information     None       2008-01-20 12:06:47                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 12:07:26                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 12:08:11                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Warning         None       2008-01-20 14:26:39                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 12 days.    
    Application  Warning         None       2008-01-20 14:32:26                                  Windows Product Activation      1011: Your Windows product has not been activated with Microsoft yet. To activate Windows, use the Product Activation Wizard.    
    Application  Warning         None       2008-01-20 14:32:30                                  Windows Product Activation      1011: Your Windows product has not been activated with Microsoft yet. To activate Windows, use the Product Activation Wizard.    
    Application  Information     2          2008-01-20 14:36:39                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-20 14:36:40                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-20 14:37:03                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         None       2008-01-20 14:37:03                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-20 14:40:46                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-20 14:40:47                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-20 18:03:53                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 18:04:25                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-20 18:05:10                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-21 00:04:08                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-21 00:04:41                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-21 00:05:24                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-21 13:36:42                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 13:36:42                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-21 13:37:06                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 13:40:58                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-21 13:40:59                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-21 16:24:03                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 16:24:03                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Warning         None       2008-01-21 16:24:28                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-21 16:24:29                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 16:28:37                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-21 16:28:40                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-21 16:32:32                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 16:32:32                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-21 16:32:55                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 16:37:25                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-21 16:37:25                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-21 16:41:00                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 16:41:00                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     1          2008-01-21 16:41:11                                  ESENT                           100: svchost (1100) The database engine 5.02.3790.3959 started.  
    Application  Information     None       2008-01-21 16:41:28                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 16:47:05                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 16:47:05                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-21 16:47:28                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 16:53:37                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-21 16:53:37                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-21 16:53:58                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-21 16:57:58                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-21 16:57:59                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-21 16:58:23                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 10 days.    
    Application  Information     None       2008-01-23 01:30:19                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-23 01:30:19                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Warning         None       2008-01-23 01:30:59                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-23 01:31:00                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-23 01:36:19                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-23 01:36:19                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-23 18:24:11                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-23 18:24:11                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-23 18:24:36                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         None       2008-01-23 18:28:38                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 8 days.    
    Application  Information     None       2008-01-23 18:31:16                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-23 18:31:17                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     2          2008-01-23 20:28:26                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-23 20:28:27                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-23 20:28:53                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-23 20:34:55                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-23 20:34:55                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Error           None       2008-01-24 00:01:03                                  VSS                             12297: Volume Shadow Copy Service error: The I/O writes cannot be flushed during the shadow copy creation period on volume D:\.  The volume index in the shadow copy set is 0. Error details: Open[0x00000000], Flush[0x80042313], Release[0x00000000], OnRun[0x00000000].  
    Application  Information     None       2008-01-24 00:05:25                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-24 00:06:00                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-24 00:06:43                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-24 08:29:20                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-24 08:29:20                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-24 08:29:45                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         None       2008-01-24 08:29:45                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-24 08:36:05                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-24 08:36:07                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-24 23:29:26                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 7 days.    
    Application  Information     None       2008-01-25 00:04:18                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 00:04:53                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 00:05:36                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 06:04:07                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 06:04:44                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 06:05:26                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 12:04:36                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 12:05:17                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-25 12:06:00                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     2          2008-01-27 17:21:06                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-27 17:21:07                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     None       2008-01-27 17:21:34                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Warning         None       2008-01-27 17:21:34                                  Perflib                         2003: The configuration information of the performance library "C:\WINDOWS\system32\perfts.dll" for the  "TermService" service does not match the trusted performance library information  stored in the registry. The functions in this library will not be treated  as trusted.  
    Application  Information     None       2008-01-27 17:30:36                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-27 17:30:37                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Warning         None       2008-01-27 18:08:07                                  Windows Product Activation      1005: Your Windows product has not been activated with Microsoft yet. Please use the Product Activation Wizard within 4 days.    
    Application  Information     None       2008-01-27 18:18:19                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-27 18:18:19                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-27 18:18:42                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-27 18:24:31                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-27 18:24:32                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-27 18:37:19                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-27 18:37:19                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-27 18:37:42                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-27 18:43:35                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-27 18:43:36                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-27 19:34:39                                  EventSystem                     4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.  
    Application  Information     2          2008-01-27 19:34:39                                  MSDTC                           4193: MS DTC started with the following settings (OFF = 0 and ON = 1):      Security Configuration:        Network Administration of Transactions = 0,        Network Clients = 0,        Inbound Distributed Transactions using Native MSDTC Protocol = 0,        Outbound Distributed Transactions using Native MSDTC Protocol = 0,        Transaction Internet Protocol (TIP) = 0,        XA Transactions = 0     Filtering Duplicate events = 1
    Application  Information     None       2008-01-27 19:35:03                                  DriveExtenderMigrator           0: Drive Extender Migrator Service started successfully. Log file is C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Home Server\logs\q_de.log.  
    Application  Information     None       2008-01-27 19:40:01                                  LoadPerf                        1001: Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully.  The Record Data contains the new values of the system Last Counter and  Last Help registry entries.  
    Application  Information     None       2008-01-27 19:40:02                                  LoadPerf                        1000: Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully.  The Record Data contains the new index values assigned  to this service.  
    Application  Information     None       2008-01-28 00:04:31                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-28 00:05:02                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-28 00:05:46                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-28 06:04:24                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-28 06:04:58                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Information     None       2008-01-28 06:05:41                                  Chkdsk                          26212: Chkdsk was executed in read-only mode on a volume snapshot.  
    Application  Error           100        2008-01-28 11:12:49                                  Application Error               1000: Faulting application vssvc.exe, version 5.2.3790.3959, faulting module vssvc.exe, version 5.2.3790.3959, fault address 0x0004a48d.  
    Security     Audit Success   2          2008-01-14 12:08:04  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31A27)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 12:15:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x72C01)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 12:15:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 12:17:43  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32AB6)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 12:25:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAE792)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 12:25:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 12:30:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBC082)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-14 12:30:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBC082)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 12:35:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE355F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 12:35:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 12:46:52  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 12:46:52  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 12:46:52  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 12:46:52  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 12:46:52  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 12:46:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC757)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   6          2008-01-14 20:33:28  SYSTEM                          Security                        612: Audit Policy Change:    New Policy:     Success Failure         +     - Logon/Logoff         -     - Object Access         -     - Privilege Use         -     - Account Management         -     - Policy Change         -     - System         -     - Detailed Tracking         -     - Directory Service Access         +     - Account Logon      Changed By:       User Name: MACHINENAME$       Domain Name:        Logon ID: (0x0,0x3E7)  
    Security     Audit Success   2          2008-01-14 21:08:26  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x36853)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2300     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:08:26  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2300    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 21:08:26  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:08:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x37ED7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:08:43  Administrator                   Security                        540: Successful Network Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x37ED7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2655    
    Security     Audit Success   9          2008-01-14 21:08:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:10:18  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3060     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2818    
    Security     Audit Success   2          2008-01-14 21:10:18  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:10:18  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3060    Source Network Address: 192.168.0.2    Source Port: 2818    
    Security     Audit Success   9          2008-01-14 21:10:18  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:11:43  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:12:16  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x492C8)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3936     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2991    
    Security     Audit Success   2          2008-01-14 21:12:16  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x492C8)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:12:16  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x492C8)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 21:12:16  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3936    Source Network Address: 192.168.0.2    Source Port: 2991    
    Security     Audit Success   2          2008-01-14 21:12:16  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-14 21:12:16  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:12:46  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:13:08  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B15E)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 388     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-14 21:13:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B15E)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:13:08  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 388    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-14 21:13:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:13:44  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4b15e)    
    Security     Audit Success   2          2008-01-14 21:13:46  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3bbb2)    
    Security     Audit Success   2          2008-01-14 21:13:47  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3BBB2)     Logon Type: 10    
    Security     Audit Success   1          2008-01-14 21:13:48                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-14 21:16:29  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:16:29  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:16:29  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:16:29  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:16:29  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:16:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB684)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:20:55  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x39102)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3492     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:20:55  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3492    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 21:20:55  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:20:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3624     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1049    
    Security     Audit Success   2          2008-01-14 21:20:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:20:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3624    Source Network Address: 192.168.0.2    Source Port: 1049    
    Security     Audit Success   9          2008-01-14 21:20:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:28:49  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x69B91)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 676     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:28:49  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6A217)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 1864     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:28:49  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 676    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-14 21:28:49  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1864    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 21:28:49  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-14 21:28:49  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:36:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8DC2F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 21:36:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:36:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8DC70)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 21:36:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:36:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E74B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 21:36:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:39:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA144B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 21:39:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-14 21:39:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:41:38  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:41:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA7578)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3772     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2414    
    Security     Audit Success   2          2008-01-14 21:41:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA7578)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:41:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3772    Source Network Address: 192.168.0.2    Source Port: 2414    
    Security     Audit Success   9          2008-01-14 21:41:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:41:47  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA7578)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 21:41:47  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:43:37  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:44:27  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB508E)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:44:27  Administrator                   Security                        540: Successful Network Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB508E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2678    
    Security     Audit Success   9          2008-01-14 21:44:27  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:44:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8DC70)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 21:44:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA144B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 21:44:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8DC2F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 21:44:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E74B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 21:46:37  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC08E3)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1992     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2809    
    Security     Audit Success   2          2008-01-14 21:46:37  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC08E3)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:46:37  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1992    Source Network Address: 192.168.0.2    Source Port: 2809    
    Security     Audit Success   9          2008-01-14 21:46:37  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:48:44  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x69B91)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 21:48:45  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB508E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 21:48:45  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x39102)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 21:48:45  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6A217)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 21:49:17  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xc08e3)    
    Security     Audit Success   2          2008-01-14 21:49:19  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3a6b4)    
    Security     Audit Success   2          2008-01-14 21:49:19  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A6B4)     Logon Type: 10    
    Security     Audit Success   1          2008-01-14 21:49:21                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-14 21:50:13  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:50:13  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:50:13  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:50:13  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:50:13  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:50:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCCDC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:51:06  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x282B9)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2960     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:51:06  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2960    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 21:51:06  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:51:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C382)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3116     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3092    
    Security     Audit Success   2          2008-01-14 21:51:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C382)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:51:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3116    Source Network Address: 192.168.0.2    Source Port: 3092    
    Security     Audit Success   9          2008-01-14 21:51:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:51:34  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3AFD5)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3696     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3109    
    Security     Audit Success   2          2008-01-14 21:51:34  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3AFD5)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:51:34  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3696    Source Network Address: 192.168.0.2    Source Port: 3109    
    Security     Audit Success   9          2008-01-14 21:51:34  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:52:06  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3afd5)    
    Security     Audit Success   2          2008-01-14 21:52:07  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C382)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 21:52:09  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2c382)    
    Security     Audit Success   2          2008-01-14 21:52:10  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C382)     Logon Type: 10    
    Security     Audit Success   1          2008-01-14 21:52:11                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-14 21:53:04  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:53:04  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:53:04  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:53:04  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:53:04  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:53:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCC2C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:54:03  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2968     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3262    
    Security     Audit Success   2          2008-01-14 21:54:03  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 21:54:03  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2968    Source Network Address: 192.168.0.2    Source Port: 3262    
    Security     Audit Success   9          2008-01-14 21:54:03  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 21:56:55  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x45DC5)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 4048     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 21:56:55  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 4048    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 21:56:55  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:00:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5F048)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:00:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:01:28  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:01:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5FD6F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:01:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:02:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5FED1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:02:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:02:49  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6083F)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2000     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 22:02:49  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2000    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 22:02:49  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:02:54  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3748     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4103    
    Security     Audit Success   2          2008-01-14 22:02:54  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 22:02:54  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3748    Source Network Address: 192.168.0.2    Source Port: 4103    
    Security     Audit Success   9          2008-01-14 22:02:54  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:04:29  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x71694)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2480     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 22:04:29  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2480    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 22:04:29  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:05:39  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x45DC5)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 22:05:43  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:07:50  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x78926)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2052     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4771    
    Security     Audit Success   2          2008-01-14 22:07:50  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x78926)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 22:07:50  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x78926)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 22:07:50  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2052    Source Network Address: 192.168.0.2    Source Port: 4771    
    Security     Audit Success   2          2008-01-14 22:07:50  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-14 22:07:50  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:12:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x87901)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:12:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:16:27  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA316B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 22:16:27  Administrator                   Security                        540: Successful Network Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA316B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1612    
    Security     Audit Success   9          2008-01-14 22:16:27  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:16:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x87901)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:16:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5FD6F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:16:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5F048)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:16:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5FED1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:20:37  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:20:58  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB8C0F)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 748     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1931    
    Security     Audit Success   2          2008-01-14 22:20:58  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB8C0F)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 22:20:58  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 748    Source Network Address: 192.168.0.2    Source Port: 1931    
    Security     Audit Success   9          2008-01-14 22:20:58  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:20:59  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB8C0F)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 22:20:59  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#4     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:21:05  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61CBF)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 22:22:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC0C34)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:22:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:25:29  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x71694)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 22:32:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF91F9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:32:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:33:57  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x100461)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 4064     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 22:33:57  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 4064    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 22:33:57  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:36:50  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA316B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:36:50  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6083F)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 22:41:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF91F9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:41:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC0C34)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:42:06  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#4     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:42:06  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#5     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:42:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111167)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:42:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:44:48  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#5     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:44:48  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#6     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 22:44:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111167)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 22:45:51  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11CC88)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 1436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 22:45:51  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1436    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 22:45:51  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:46:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D0F6)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 22:46:08  Administrator                   Security                        540: Successful Network Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D0F6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3995    
    Security     Audit Success   9          2008-01-14 22:46:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:52:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14979E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 22:52:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 22:54:57  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x100461)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 23:02:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x169481)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 23:02:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:06:52  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D0F6)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:06:52  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11CC88)     Logon Type: 8    
    Security     Audit Success   2          2008-01-14 23:13:44  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B7497)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3620     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:13:44  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3620    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:13:44  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:16:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x169481)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:16:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14979E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:16:27  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#6     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 23:16:52  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Session Name: RDP-Tcp#7     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 23:25:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E257D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 23:25:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:25:45  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EB0B2)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3572     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:25:45  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3572    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:25:45  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:28:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F0394)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3572     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:28:19  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3572    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:28:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:31:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FA086)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1942    
    Security     Audit Success   2          2008-01-14 23:31:29  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FA03D)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3352     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:31:29  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3352    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:31:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-14 23:31:29  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:32:30  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FA086)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:35:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20923F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 23:35:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:40:01  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)    
    Security     Audit Success   2          2008-01-14 23:40:02  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29683)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 23:45:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x227FFA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 23:45:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:50:15  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B077)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3532     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2079    
    Security     Audit Success   2          2008-01-14 23:50:15  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B077)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 23:50:15  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3532    Source Network Address: 192.168.0.2    Source Port: 2079    
    Security     Audit Success   9          2008-01-14 23:50:15  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:50:59  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B077)     Session Name: RDP-Tcp#9     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-14 23:52:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2441A2)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3104     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2088    
    Security     Audit Success   2          2008-01-14 23:52:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2441A2)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 23:52:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3104    Source Network Address: 192.168.0.2    Source Port: 2088    
    Security     Audit Success   9          2008-01-14 23:52:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:52:31  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2441A2)     Logon Type: 10    
    Security     Audit Success   2          2008-01-14 23:52:31  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B077)     Session Name: RDP-Tcp#10     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   1          2008-01-14 23:53:23                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-14 23:54:40  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:54:40  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 23:54:40  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:54:40  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-14 23:54:40  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:54:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCA87)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:55:12  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27ABB)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2976     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:55:12  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2976    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:55:12  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:55:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2850E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-14 23:55:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:56:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31867)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-14 23:56:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:56:59  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31867)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:57:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x31A1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-14 23:57:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31A27)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-14 23:57:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:57:08  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32AB6)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3292     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-14 23:57:08  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3292    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-14 23:57:08  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-14 23:57:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x31A1D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:57:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x34209)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-14 23:57:28  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x34209)     Logon Type: 3    
    Security     Audit Success   2          2008-01-14 23:58:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3456A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-14 23:58:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3456A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 00:03:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x493F2)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 208     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2112    
    Security     Audit Success   2          2008-01-15 00:03:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x493F2)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 00:03:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 208    Source Network Address: 192.168.0.2    Source Port: 2112    
    Security     Audit Success   9          2008-01-15 00:03:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 00:05:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5B1B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 00:05:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 00:47:52  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3EA96)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2992     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 00:47:52  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2992    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 00:47:52  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 00:48:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4155F)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3112     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1178    
    Security     Audit Success   2          2008-01-15 00:48:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4155F)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 00:48:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3112    Source Network Address: 192.168.0.2    Source Port: 1178    
    Security     Audit Success   9          2008-01-15 00:48:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 00:55:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD9BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 00:55:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 00:56:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x10F6C8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 00:56:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x10F6C8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:04:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23609D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:04:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:13:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3C886D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:13:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:14:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4687C9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 01:14:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4687C9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:14:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x46887B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 01:14:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x46887B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:14:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x468894)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 01:14:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:14:48  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x468894)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:21:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x752BFC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:21:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:24:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7CCED1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 01:24:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7CCED1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:30:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90CE50)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:30:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:38:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB24152)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:38:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:46:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD05547)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:46:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 01:51:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDEA990)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 01:51:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDEA990)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 01:55:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF80113)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 01:55:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:03:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1313E05)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:03:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:11:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16A116B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:11:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:18:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x193FBEB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 02:18:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x193FBEB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 02:20:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A24AA7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:20:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:28:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DA4AAD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:28:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:37:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2141481)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:37:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:44:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22B377F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 02:44:43  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22B377F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 02:45:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B37F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:45:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 02:53:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22EE5F2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 02:53:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:02:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22EF0EF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:02:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:10:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F0021)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:10:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:11:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22F0133)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 03:11:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22F0133)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 03:18:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F0CD7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:18:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:27:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x232B889)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:27:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:35:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2377399)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:35:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:38:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2377A35)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 03:38:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2377A35)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 03:43:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23A3E3D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:43:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 03:52:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B2C11)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 03:52:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:00:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B3BFE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:00:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:04:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x23B424F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:04:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x23B424F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 04:08:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B4B40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:08:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:17:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23EF47E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:17:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:25:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F060C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:25:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:31:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x23F0E86)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:31:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x23F0E86)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 04:34:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F1302)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:34:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:35:45  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: MACHINENAME$     Caller Domain:      Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 304     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:35:45  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:35:45  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: MACHINENAME$     Caller Domain:      Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 304     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:35:45  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:37:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBD194)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:37:54  IWAM_WEBERSERVER                Security                        576: Special privileges assigned to new logon:     User Name: IWAM_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCAC4D)     Privileges: SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:37:54  IWAM_WEBERSERVER                Security                        538: User Logoff:     User Name: IWAM_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCAC4D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 04:37:54  IWAM_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IWAM_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCAC4D)     Logon Type: 3     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: MACHINENAME$     Caller Domain:      Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1836     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:37:54  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: MACHINENAME$     Domain:       Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: IWAM_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1836    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 04:37:54  IWAM_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IWAM_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:42:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F200A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:42:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   1          2008-01-15 04:42:46                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 04:43:51  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:43:51  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:43:51  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:43:51  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:43:51  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:43:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCCEB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:44:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A2E)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 388     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:44:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name:      Domain:       Logon ID:  (0x0,0x13A2E)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:44:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 388    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 04:44:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:44:27  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13a2e)    
    Security     Audit Success   2          2008-01-15 04:44:28  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A2E)     Logon Type: 2    
    Security     Audit Success   1          2008-01-15 04:44:33                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 04:47:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAC11)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 376     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:47:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAC11)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:47:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC2E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:47:42  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:47:42  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:47:42  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:47:42  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:47:42  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:47:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 376    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 04:47:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:48:12  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xac11)    
    Security     Audit Success   2          2008-01-15 04:48:13  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAC11)     Logon Type: 2    
    Security     Audit Success   1          2008-01-15 04:48:15                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 04:49:13  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAB6C)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 376     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:49:13  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAB6C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:49:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC28D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:49:13  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:49:13  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:49:13  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:49:13  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:49:13  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:49:13  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 376    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 04:49:13  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-15 04:50:02  ASPNET                          Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: ASPNET    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:50:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242CBBC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:50:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:56:43  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xab6c)    
    Security     Audit Success   1          2008-01-15 04:56:47                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 04:57:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111B1)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 376     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:57:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111B1)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:57:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xEAF8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:57:42  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:57:42  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:57:42  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 424     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:57:42  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:57:42  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 04:57:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 376    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 04:57:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:58:08  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111b1)    
    Security     Audit Success   2          2008-01-15 04:58:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6385B)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 376     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:58:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6385B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 04:58:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 376    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 04:58:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 04:58:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x242D9AB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 04:58:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x242D9AB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 04:59:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242DADD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 04:59:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:03:12  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x111B1)     Logon Type: 2    
    Security     Audit Success   2          2008-01-15 05:07:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242E652)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:07:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:10:06  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6385b)    
    Security     Audit Success   1          2008-01-15 05:10:07                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 05:10:07  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6385B)     Logon Type: 2    
    Security     Audit Success   2          2008-01-15 05:15:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24693A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:15:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:22:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC3C6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:22:22  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:22:22  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:22:22  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:22:22  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:22:22  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:24:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246A03D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:24:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:24:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x246A170)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 05:24:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x246A170)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 05:32:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246AE2C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:32:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   1          2008-01-15 05:32:59                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 05:36:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCA3A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:36:24  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:36:24  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:36:24  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:36:24  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:36:24  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:37:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC77E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:37:54  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:37:54  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:37:54  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:37:54  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:37:54  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 05:37:57  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24325)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 388     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-01-15 05:37:57  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24325)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 05:37:57  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORKGROUP     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 388    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-01-15 05:37:57  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:40:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246BB4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:40:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:49:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A6892)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:49:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 05:51:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x24A6BC4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 05:51:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x24A6BC4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 05:57:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A7602)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 05:57:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-15 06:05:18  ASPNET                          Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: ASPNET    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:05:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24F5B94)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:05:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:09:06  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 06:09:06  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 06:09:06  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORKGROUP     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 436     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 06:09:06  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 06:09:06  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 06:09:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC4F2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 06:14:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25308CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:14:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:18:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25310D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 06:18:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25310D1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 06:22:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2531628)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:22:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:30:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x253252E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:30:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:39:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25331B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:39:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:44:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x256DA71)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 06:44:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x256DA71)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 06:47:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256DDEC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:47:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 06:55:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256EA5A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 06:55:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:04:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256F99A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:04:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:11:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25703E8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 07:11:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25703E8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 07:12:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2570596)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:12:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:20:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25AB2B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:20:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:29:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25ABFB8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:29:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:37:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25ACD44)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:37:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:38:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25ACF47)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 07:38:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25ACF47)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 07:45:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E7A2D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:45:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 07:54:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E86E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 07:54:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 08:02:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E94DF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 08:02:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 08:04:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25EAFAD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 08:04:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25EAFAD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:10:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26930C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 08:10:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 08:19:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26FA9A3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 08:19:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 08:21:59  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4155F)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F060C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B3BFE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242E652)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24F5B94)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3C886D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246A03D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16A116B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B4B40)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246AE2C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF80113)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2531628)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26FA9A3)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23609D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB24152)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242DADD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26930C2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2570596)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F1302)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23F200A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F0CD7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2377399)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23A3E3D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A6892)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1313E05)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256F99A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90CE50)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A24AA7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256DDEC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E94DF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25308CD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24693A2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x232B889)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x253252E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22EF0EF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x256EA5A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A7602)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25331B1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E86E9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD05547)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x242CBBC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22EE5F2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F0021)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25ABFB8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25AB2B2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x752BFC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD9BA)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246BB4D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25E7A2D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B2C11)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2141481)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B37F4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DA4AAD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25ACD44)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 08:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23EF47E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 18:13:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E47759)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 18:13:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:14:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E55A4F)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2688     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1059    
    Security     Audit Success   2          2008-01-15 18:14:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E55A4F)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 18:14:31  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E55A4F)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 18:14:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2688    Source Network Address: 192.168.0.2    Source Port: 1059    
    Security     Audit Success   2          2008-01-15 18:14:31  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4155F)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-15 18:14:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:14:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E56607)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 18:14:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E56607)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 18:23:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2ED25A6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 18:23:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:37:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 18:37:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 18:37:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 18:37:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 18:37:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 18:37:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCBCC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 18:37:46  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28A29)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2980     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 18:37:46  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2980    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 18:37:46  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:38:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F3FB)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3188     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1164    
    Security     Audit Success   2          2008-01-15 18:38:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F3FB)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 18:38:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3188    Source Network Address: 192.168.0.2    Source Port: 1164    
    Security     Audit Success   9          2008-01-15 18:38:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:44:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA026D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 18:44:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 18:46:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA8727)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 18:46:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA8727)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 18:54:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD194B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 18:54:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 19:01:56  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F3FB)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 19:02:06  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD194B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 19:02:06  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA026D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 19:02:16  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F3FB)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 19:04:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x113791)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 19:04:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 19:11:42  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2f3fb)    
    Security     Audit Success   1          2008-01-15 19:11:48                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-15 20:05:49  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 20:05:49  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 20:05:49  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 20:05:49  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 20:05:49  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 20:05:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCDFB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 20:06:20  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284C5)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2976     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 20:06:20  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2976    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 20:06:20  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:07:50  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304D3)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3244     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1637    
    Security     Audit Success   2          2008-01-15 20:07:50  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304D3)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 20:07:50  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3244    Source Network Address: 192.168.0.2    Source Port: 1637    
    Security     Audit Success   9          2008-01-15 20:07:50  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:11:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6104A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 20:11:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:11:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6104A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:11:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6466D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:11:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6466D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:11:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x648AF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:11:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x648AF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:11:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64969)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 20:11:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:11:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x64B1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:11:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x64B1D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:17:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64969)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:17:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x81B40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:17:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x81B40)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:17:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x81B51)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:17:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x81B51)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:17:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81D16)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 20:17:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:17:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x82598)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:17:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x82598)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:23:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA55A8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:23:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA55A8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:32:06  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304D3)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 20:32:18  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFD910)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3276     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1901    
    Security     Audit Success   2          2008-01-15 20:32:18  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFD910)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 20:32:18  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFD910)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 20:32:18  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3276    Source Network Address: 192.168.0.2    Source Port: 1901    
    Security     Audit Success   2          2008-01-15 20:32:18  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304D3)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-15 20:32:18  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:35:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x121262)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:35:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x121262)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:45:08  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304d3)    
    Security     Audit Success   2          2008-01-15 20:45:17  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x304D3)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 20:52:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x234DE6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:52:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x234DE6)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:52:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x23635B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:53:01  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x23635B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:53:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x245442)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:53:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x245442)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 20:53:44  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25C0EA)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2296     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2045    
    Security     Audit Success   2          2008-01-15 20:53:44  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25C0EA)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 20:53:44  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2296    Source Network Address: 192.168.0.2    Source Port: 2045    
    Security     Audit Success   9          2008-01-15 20:53:44  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 20:55:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x299369)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 20:55:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x299369)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 21:27:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x543B5E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 21:27:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x543B5E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 21:33:12  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25c0ea)    
    Security     Audit Success   2          2008-01-15 21:33:16  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25C0EA)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 21:51:39  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81D16)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 21:59:22  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284C5)     Logon Type: 8    
    Security     Audit Success   2          2008-01-15 21:59:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x65F09C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 21:59:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:00:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6654C6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 169.254.215.163     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:00:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6654C6)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:00:47  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6674F0)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3648     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 22:00:47  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3648    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 22:00:47  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:01:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3692     Transited Services: -     Source Network Address: 169.254.215.163     Source Port: 1071    
    Security     Audit Success   2          2008-01-15 22:01:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:01:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3692    Source Network Address: 169.254.215.163    Source Port: 1071    
    Security     Audit Success   9          2008-01-15 22:01:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:01:23  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#5     Client Name: BIER     Client Address: 169.254.215.163  
    Security     Audit Success   2          2008-01-15 22:02:58  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x65F09C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:09:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6CF97F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:09:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:10:49  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6CF97F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:16:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73ECB3)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2612     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1541    
    Security     Audit Success   2          2008-01-15 22:16:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73ECB3)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:16:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2612    Source Network Address: 192.168.0.2    Source Port: 1541    
    Security     Audit Success   2          2008-01-15 22:16:30  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#6     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-15 22:16:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:16:31  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73ECB3)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 22:17:01  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x747BF3)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 276     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-15 22:17:01  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 276    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-15 22:17:01  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:19:23  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#6     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:19:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x77753A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:19:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:19:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x779FDE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:19:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x779FDE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:19:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x77A1A5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:19:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x77A1A5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:20:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x77BA36)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:20:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x77BA36)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:20:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x77BBF5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:20:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x77BBF5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:20:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x77CF8B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 22:20:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:20:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x77D921)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:20:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x77D921)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:29:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7D47E3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:29:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:32:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7E69CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 22:32:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7E69CD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:33:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7EAB00)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1820     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1646    
    Security     Audit Success   2          2008-01-15 22:33:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7EAB00)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:33:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1820    Source Network Address: 192.168.0.2    Source Port: 1646    
    Security     Audit Success   9          2008-01-15 22:33:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:33:12  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7EAB00)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 22:33:12  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#7     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:35:55  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802EBF)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3668     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1663    
    Security     Audit Success   2          2008-01-15 22:35:55  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802EBF)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:35:55  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3668    Source Network Address: 192.168.0.2    Source Port: 1663    
    Security     Audit Success   9          2008-01-15 22:35:55  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:36:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x77CF8B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:36:15  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802EBF)     Session Name: RDP-Tcp#8     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:36:15  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#7     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:36:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x77753A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:36:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7D47E3)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:36:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x811AC5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 22:36:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:36:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x811AC5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 22:37:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81A283)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 22:37:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:37:53  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81C091)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 620     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1678    
    Security     Audit Success   2          2008-01-15 22:37:53  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81C091)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:37:53  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81C091)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 22:37:53  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 620    Source Network Address: 192.168.0.2    Source Port: 1678    
    Security     Audit Success   2          2008-01-15 22:37:53  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#9     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-15 22:37:53  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:39:29  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#9     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:39:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x82B9FF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:39:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:42:49  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x839D05)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3624     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1689    
    Security     Audit Success   2          2008-01-15 22:42:49  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x839D05)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 22:42:49  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3624    Source Network Address: 192.168.0.2    Source Port: 1689    
    Security     Audit Success   9          2008-01-15 22:42:49  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:42:50  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x839D05)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 22:42:50  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802EBF)     Session Name: RDP-Tcp#10     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-15 22:43:27  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802ebf)    
    Security     Audit Success   2          2008-01-15 22:43:38  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x802EBF)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 22:49:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x87C577)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:49:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 22:58:54  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6674F0)     Logon Type: 8    
    Security     Audit Success   2          2008-01-15 22:59:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8D0EA2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 22:59:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:00:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81A283)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:00:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E0BEC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 23:00:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:04:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x907B93)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 23:04:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x907B93)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:09:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x950D03)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 23:09:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:09:56  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9532A4)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3912     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1911    
    Security     Audit Success   2          2008-01-15 23:09:56  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9532A4)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-15 23:09:56  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3912    Source Network Address: 192.168.0.2    Source Port: 1911    
    Security     Audit Success   9          2008-01-15 23:09:56  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:19:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9B8F45)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-15 23:19:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:21:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E0BEC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:23:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9C4456)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-15 23:23:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-15 23:23:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9C44C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 23:23:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9C44C2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:23:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9C450F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 23:23:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9C450F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:23:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9C6300)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 23:23:43  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9C6300)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:23:44  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9C6348)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-15 23:23:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9C6348)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:24:38  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9532a4)    
    Security     Audit Success   2          2008-01-15 23:24:40  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9532A4)     Logon Type: 10    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x82B9FF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x950D03)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9B8F45)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8D0EA2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x87C577)     Logon Type: 3    
    Security     Audit Success   2          2008-01-15 23:26:07  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9C4456)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 03:17:05  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x747BF3)     Logon Type: 8    
    Security     Audit Success   2          2008-01-17 03:31:47  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B322589)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2156     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 03:31:47  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2156    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-17 03:31:47  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 17:59:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A1CD291)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 17:59:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:00:14  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A20EF22)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3324     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1105    
    Security     Audit Success   2          2008-01-17 18:00:14  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A20EF22)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:00:14  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3324    Source Network Address: 192.168.0.2    Source Port: 1105    
    Security     Audit Success   9          2008-01-17 18:00:14  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:01:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A26C9B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:01:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A26C9B4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:09:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A697597)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 18:09:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:19:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A9FAACB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 18:19:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:21:03  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2a20ef22)    
    Security     Audit Success   2          2008-01-17 18:21:05  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A20EF22)     Logon Type: 10    
    Security     Audit Success   2          2008-01-17 18:21:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2AA5233A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:21:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AA52371)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-17 18:21:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:21:29  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2AA5233A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:21:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2AA65C6C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:21:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2AA65C6C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:21:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2AA65E27)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:21:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2AA65E27)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:21:31  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AA52371)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A9FAACB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A1CD291)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A697597)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:22:37  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AAA0ED0)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3864     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:22:37  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3864    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-17 18:22:37  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:22:45  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AAA36E7)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3124     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1340    
    Security     Audit Success   2          2008-01-17 18:22:45  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AAA36E7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:22:45  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3124    Source Network Address: 192.168.0.2    Source Port: 1340    
    Security     Audit Success   2          2008-01-17 18:22:45  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#13     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-17 18:22:45  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:22:46  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AAA36E7)     Logon Type: 10    
    Security     Audit Success   2          2008-01-17 18:24:09  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#13     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-17 18:24:37  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#14     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-17 18:29:05  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#14     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-17 18:29:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AB4F5DF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 18:29:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:34:21  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2ABE7387)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2492     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1787    
    Security     Audit Success   2          2008-01-17 18:34:21  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2ABE7387)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:34:21  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2ABE7387)     Logon Type: 10    
    Security     Audit Success   2          2008-01-17 18:34:21  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2492    Source Network Address: 192.168.0.2    Source Port: 1787    
    Security     Audit Success   2          2008-01-17 18:34:21  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66AA1C)     Session Name: RDP-Tcp#15     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-17 18:34:21  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-01-17 18:34:44                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-17 18:36:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:36:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:36:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:36:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:36:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:36:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDCAA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:36:47  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B1DF)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3020     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-17 18:36:47  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3020    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-17 18:36:47  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:37:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x35C10)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 18:37:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:37:57  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3DECE)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3312     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1832    
    Security     Audit Success   2          2008-01-17 18:37:57  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3DECE)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-17 18:37:57  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3312    Source Network Address: 192.168.0.2    Source Port: 1832    
    Security     Audit Success   9          2008-01-17 18:37:57  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:39:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5BCEB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:39:43  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5BCEB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:39:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5C1A9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:39:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5C1A9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:39:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5C5DC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:39:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5C5DC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:39:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5C722)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:39:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5C722)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:39:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5C77B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-17 18:39:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:39:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5D77D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-17 18:40:01  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5D77D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-17 18:47:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15B87F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-17 18:47:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-17 18:52:08  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3dece)    
    Security     Audit Success   1          2008-01-17 18:52:16                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-19 11:46:53  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:46:53  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 11:46:53  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:46:53  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 11:46:53  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:46:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD9BC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:47:27  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AFA9)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3032     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:47:27  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3032    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 11:47:27  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:47:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31561)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 11:47:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:49:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4AC27)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:49:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4AC27)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:51:02  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E0BB)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3668     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 11:51:02  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3668    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 11:51:02  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:51:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64286)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3840     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1148    
    Security     Audit Success   2          2008-01-19 11:51:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64286)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 11:51:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3840    Source Network Address: 192.168.0.2    Source Port: 1148    
    Security     Audit Success   9          2008-01-19 11:51:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:51:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x64718)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:51:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x64718)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:51:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x64840)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:51:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x64840)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:51:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6653A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:51:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6653A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:51:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x665A7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:51:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x665A7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:51:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66B45)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 11:51:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:51:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x671E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:51:28  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x671E7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:53:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC0E8D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:53:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC0E8D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:53:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC8474)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:53:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC8474)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:53:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC87E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 11:54:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC87E9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 11:54:57  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64286)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 11:55:08  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEB598)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 596     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1235    
    Security     Audit Success   2          2008-01-19 11:55:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEB598)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 11:55:08  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 596    Source Network Address: 192.168.0.2    Source Port: 1235    
    Security     Audit Success   9          2008-01-19 11:55:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 11:57:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1327AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 11:57:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:04:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17FD55)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 12:04:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x17FD55)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:08:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A53B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:08:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:09:05  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x66B45)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:12:10  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E0BB)     Logon Type: 8    
    Security     Audit Success   2          2008-01-19 12:17:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21BFE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 12:17:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21BFF1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 12:17:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:17:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21BFE7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:18:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24B6BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:18:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:21:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A6841)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 12:21:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A6841)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:24:00  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xeb598)    
    Security     Audit Success   2          2008-01-19 12:24:05  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64286)    
    Security     Audit Success   2          2008-01-19 12:24:14  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x64286)     Logon Type: 10    
    Security     Audit Success   1          2008-01-19 12:24:16                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-19 12:25:22  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:22  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 12:25:22  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:22  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 12:25:22  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:28  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDE20)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEF5B)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEF5B)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-19 12:25:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 440    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 12:25:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:25:58  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D50D)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3112     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 12:25:58  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3112    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 12:25:58  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:26:21  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3236     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1348    
    Security     Audit Success   2          2008-01-19 12:26:21  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 12:26:21  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3236    Source Network Address: 192.168.0.2    Source Port: 1348    
    Security     Audit Success   9          2008-01-19 12:26:21  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:28:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5A91B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:28:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:30:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8C5BC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 12:30:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:30:19  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8C5BC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:32:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA05EC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 12:32:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:32:37  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA05EC)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:38:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10DD7D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:38:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:47:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AC609)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 12:47:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:47:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AC609)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:48:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B10A3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:48:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:53:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DC878)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 12:53:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DC878)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:56:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F985F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 12:56:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 12:56:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FAD97)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 12:56:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FAD97)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 12:58:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20F496)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 12:58:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:08:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25A640)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 13:08:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:12:08  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:12:08  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:12:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25A640)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20F496)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10DD7D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5A91B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B10A3)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:22  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:12:23  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:12:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F985F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:12:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x291A8C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:12:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:13:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x291D93)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:13:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x291D93)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:13:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x291A8C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:13:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x294745)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:13:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x294745)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:13:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2948EB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:13:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2948EB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:13:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x294A69)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:13:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:13:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x294CCD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:13:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x294CCD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:17:55  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x294A69)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:17:56  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:18:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E8C3D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:18:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:18:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E8C3D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:19:34  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)     Session Name: RDP-Tcp#4     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 13:21:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x321726)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:21:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:21:56  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x321726)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:21:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3271FB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:21:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:22:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3271FB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:22:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32C033)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:22:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:23:21  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32220)    
    Security     Audit Success   1          2008-01-19 13:23:33                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-19 13:24:41  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:24:41  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 13:24:41  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:24:41  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 13:24:41  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:24:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5A796)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:24:52  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5B777)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:24:52  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5B777)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-19 13:24:52  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 456    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 13:24:52  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:25:16  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x78A4D)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3132     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:25:16  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3132    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 13:25:16  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:25:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7C515)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:25:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7C515)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:26:24  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x85955)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3440     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2201    
    Security     Audit Success   2          2008-01-19 13:26:24  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x85955)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 13:26:24  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3440    Source Network Address: 192.168.0.2    Source Port: 2201    
    Security     Audit Success   9          2008-01-19 13:26:24  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:28:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB492E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 13:28:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:38:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFD820)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 13:38:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:42:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x129974)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:42:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x129974)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:42:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12997E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 13:42:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:42:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12ADDE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:43:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12ADDE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:48:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x161F1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 13:48:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:57:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1CEC10)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 13:57:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1CEC10)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 13:58:34  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D4F69)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2420     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 13:58:34  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2420    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 13:58:34  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:58:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6507)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 13:58:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 13:59:49  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DCF0A)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 384     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2318    
    Security     Audit Success   2          2008-01-19 13:59:49  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DCF0A)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 13:59:49  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 384    Source Network Address: 192.168.0.2    Source Port: 2318    
    Security     Audit Success   9          2008-01-19 13:59:49  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:08:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x248DAD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:08:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:09:04  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DCF0A)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 14:09:34  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x85955)    
    Security     Audit Success   2          2008-01-19 14:09:42  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x85955)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 14:18:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BC671)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:18:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:19:47  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D4F69)     Logon Type: 8    
    Security     Audit Success   2          2008-01-19 14:28:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3363D7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:28:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:29:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x33A66D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 14:29:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x33A66D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 14:38:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3AE307)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:38:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:48:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x430EEE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:48:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 14:58:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x497C17)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 14:58:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:01:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4ACE63)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 15:01:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4ACE63)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 15:04:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4CF8B0)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3528     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2816    
    Security     Audit Success   2          2008-01-19 15:04:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4CF8B0)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 15:04:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3528    Source Network Address: 192.168.0.2    Source Port: 2816    
    Security     Audit Success   9          2008-01-19 15:04:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:08:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x50DD1B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:08:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:18:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x597FDA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:18:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:28:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x62CD9A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:28:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:33:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x665C42)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 15:33:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x665C42)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 15:38:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6BDCEF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:38:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:48:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x71F755)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:48:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 15:59:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x894565)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 15:59:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:05:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x8B8CA4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 16:05:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x8B8CA4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 16:09:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8D2D5D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:09:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:19:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x930C1E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:19:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:29:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x951ABF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:29:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:37:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x96D1EF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 16:37:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x96D1EF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 16:39:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x972044)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:39:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:49:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x997AEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:49:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 16:59:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9BD3E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 16:59:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:09:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9F154B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:09:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:09:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F43D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 17:09:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F43D4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 17:19:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA3367C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:19:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:29:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA6CB52)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:29:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:39:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAACAF1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:39:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:40:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAAF7D5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 17:40:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAAF7D5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 17:41:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAB3A9A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 17:41:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAB3A9A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 17:49:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB44290)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:49:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 17:59:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB8C70A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 17:59:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:09:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBAC496)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:09:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:13:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBB396C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 18:13:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBB396C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 18:19:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBBDFA4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:19:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:22:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBD9342)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 18:22:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBD9342)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 18:29:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC08D62)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:29:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:29:52  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4cf8b0)    
    Security     Audit Success   2          2008-01-19 18:30:01  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4CF8B0)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 18:39:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC3CBB6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:39:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:45:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC53EC0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 18:45:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC53EC0)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 18:49:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC60A23)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:49:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 18:59:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3BEF9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 18:59:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:09:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF39D8A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:09:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:13:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x110371C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:13:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x110371C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:14:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x110930B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:14:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x110930B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:14:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12997E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:17:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x114BF8F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:17:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x114BF8F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:18:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x116D794)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 19:18:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:18:56  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x116D794)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:19:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11857CC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:19:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:19:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1185C13)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:19:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1185C13)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:19:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1185C33)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:19:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1185C33)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:19:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1185C47)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 19:19:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:19:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1185C47)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:19:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1187098)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 19:19:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:29:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12E61AF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:29:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:31:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1347216)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:32:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1347216)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:33:49  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1393F18)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 140     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 19:33:49  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 140    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 19:33:49  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:34:01  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x139638D)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 244     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4615    
    Security     Audit Success   2          2008-01-19 19:34:01  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x139638D)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 19:34:01  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x139638D)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 19:34:01  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 244    Source Network Address: 192.168.0.2    Source Port: 4615    
    Security     Audit Success   2          2008-01-19 19:34:01  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DCF0A)     Session Name: RDP-Tcp#4     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   9          2008-01-19 19:34:01  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:35:20  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A3FF5)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2168     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4619    
    Security     Audit Success   2          2008-01-19 19:35:20  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A3FF5)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 19:35:20  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2168    Source Network Address: 192.168.0.2    Source Port: 4619    
    Security     Audit Success   9          2008-01-19 19:35:20  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:36:05  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DCF0A)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 19:39:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1443314)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:39:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:41:14  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A3FF5)     Session Name: RDP-Tcp#5     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-19 19:42:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14B71F1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:42:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14B71F1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:46:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14FE432)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:46:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14FE432)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:46:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FF46E)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3100     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4629    
    Security     Audit Success   2          2008-01-19 19:46:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FF46E)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 19:46:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3100    Source Network Address: 192.168.0.2    Source Port: 4629    
    Security     Audit Success   9          2008-01-19 19:46:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:48:51  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A3FF5)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 19:49:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x154E0B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:49:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:49:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x154F2E5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 19:49:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x154F2E5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 19:54:47  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FF46E)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 724    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-19 19:54:47  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FF46E)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 3124    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-19 19:54:48  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FF46E)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 3124    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-19 19:55:52  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1393F18)     Logon Type: 8    
    Security     Audit Success   2          2008-01-19 19:56:20  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14ff46e)    
    Security     Audit Success   2          2008-01-19 19:57:29  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1607023)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3028     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4661    
    Security     Audit Success   2          2008-01-19 19:57:29  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1607023)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 19:57:29  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3028    Source Network Address: 192.168.0.2    Source Port: 4661    
    Security     Audit Success   9          2008-01-19 19:57:29  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:59:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x162E13F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 19:59:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 19:59:27  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1607023)    
    Security     Audit Success   1          2008-01-19 19:59:32                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-19 20:00:32  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:00:32  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 20:00:32  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:00:32  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 20:00:32  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:00:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x535F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:00:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57E23)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 440     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:00:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57E23)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-19 20:00:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 440    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 20:00:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:01:11  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x70C6F)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3172     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-19 20:01:11  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3172    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-19 20:01:11  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:01:29  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73166)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3292     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4674    
    Security     Audit Success   2          2008-01-19 20:01:29  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73166)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 20:01:29  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3292    Source Network Address: 192.168.0.2    Source Port: 4674    
    Security     Audit Success   9          2008-01-19 20:01:29  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:09:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC721B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 20:09:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:15:14  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73166)    
    Security     Audit Success   2          2008-01-19 20:15:17  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x73166)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 20:19:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x195224)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 20:19:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:20:51  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B8132)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3428     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 4754    
    Security     Audit Success   2          2008-01-19 20:20:51  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B8132)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-19 20:20:51  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3428    Source Network Address: 192.168.0.2    Source Port: 4754    
    Security     Audit Success   9          2008-01-19 20:20:51  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:21:10  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1b8132)    
    Security     Audit Success   2          2008-01-19 20:21:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E5E10)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 20:21:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E5E10)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:22:42  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B8132)     Logon Type: 10    
    Security     Audit Success   2          2008-01-19 20:29:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DF8D7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 20:29:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:30:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2F638E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-19 20:30:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F6398)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 20:30:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:30:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2F638E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:30:51  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F6398)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:39:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3CA7DB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-19 20:39:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:39:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3D8EBF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-19 20:39:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-19 20:40:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3D8EBF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:40:10  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x195224)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:40:10  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3CA7DB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:40:10  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC721B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-19 20:40:10  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DF8D7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:50:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95C15A1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 10:50:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 10:51:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x95FC123)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:51:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x95FC123)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:52:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x960F96D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:52:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x960F978)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:52:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x960F978)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:52:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x960F9B9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-20 10:52:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   9          2008-01-20 10:52:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 10:53:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x960F96D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:54:29  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x964D223)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:54:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x964D223)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:55:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x960F9B9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:55:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x965A975)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:55:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x965A97F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-20 10:55:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 10:55:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x965A975)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:56:01  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x965A97F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 10:56:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x965AF8F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 10:56:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x965AF99)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-20 10:56:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 10:56:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x965AF8F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:00:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x96BEE37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:00:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:10:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9751634)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:10:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:20:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9806FB8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:20:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:23:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x984DC6D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:23:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x984DC6D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:25:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9852DC1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:25:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9852DC1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:25:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9853487)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:25:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9853487)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:25:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9853699)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:25:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9853699)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:25:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9853D76)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:26:07  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9853D76)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 11:30:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9861E70)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:30:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:40:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9A3E02D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:40:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:50:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9B1EA84)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 11:50:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 11:55:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9D27CB1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 11:55:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9D27CB1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 12:00:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DF92DB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:00:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:10:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9E52F8B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:10:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:11:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9E6D1B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 12:11:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9E6D1B0)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 12:11:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9E7E423)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 12:11:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9E7E423)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 12:20:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA0916E0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:20:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:27:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA297EDD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 12:27:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA297EDD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 12:30:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA2E7BAF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:30:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:40:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA48260E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:40:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:50:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA5DD3EB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 12:50:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 12:59:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA73C88A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 12:59:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA73C88A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 13:00:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA742F6C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:00:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 13:10:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA90C239)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:10:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 13:20:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAAD3E6B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:20:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 13:30:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAC1EB95)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:30:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 13:31:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAC5BE9B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 13:31:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAC5BE9B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 13:40:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xADE73AD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:40:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 13:50:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAFA514E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 13:50:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:00:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB14CCB5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:00:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB14CCB5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:00:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB163917)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:00:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:01:29  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB19C095)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:01:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB19C095)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:03:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB2147AD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:03:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB2147AD)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:10:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB30A8BF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:10:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:20:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB4A8E32)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:20:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:24:17  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB5290F4)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2268     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1891    
    Security     Audit Success   2          2008-01-20 14:24:17  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB5290F4)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-20 14:24:17  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2268    Source Network Address: 192.168.0.2    Source Port: 1891    
    Security     Audit Success   9          2008-01-20 14:24:17  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:27:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB5AB6B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:27:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB5AB6B1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:27:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB5ABEDE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:27:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB5ABEDE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:27:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB5B501A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:27:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB5B501A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:27:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB5B503D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 14:28:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB5B503D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 14:30:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB613186)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:30:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:35:28  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xb5290f4)    
    Security     Audit Success   1          2008-01-20 14:35:33                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-20 14:36:34  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:36:34  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-20 14:36:34  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:36:34  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-20 14:36:34  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:36:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19CA37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:36:44  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19DCF3)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:36:44  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19DCF3)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-20 14:36:44  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 456    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-20 14:36:44  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:37:06  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B918B)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2968     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2040    
    Security     Audit Success   2          2008-01-20 14:37:06  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B918B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-20 14:37:06  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2968    Source Network Address: 192.168.0.2    Source Port: 2040    
    Security     Audit Success   9          2008-01-20 14:37:06  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:37:08  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA3CF)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3228     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-20 14:37:08  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3228    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-20 14:37:08  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:38:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CE5B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-20 14:38:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:40:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E29C6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:40:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 14:50:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x297F8D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 14:50:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:00:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4194E5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:00:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:07:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4D469F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 15:07:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4D469F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 15:09:18  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1b918b)    
    Security     Audit Success   2          2008-01-20 15:09:21  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B918B)     Logon Type: 10    
    Security     Audit Success   2          2008-01-20 15:10:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EC593)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:10:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:16:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CE5B1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 15:19:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5EC690)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 15:19:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5EC6A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-20 15:19:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:19:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5EC690)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 15:20:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x622AFA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:20:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:20:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6362EA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 15:20:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6362EA)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 15:30:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7FA14E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:30:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:37:13  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x96E289)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3716     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2405    
    Security     Audit Success   2          2008-01-20 15:37:13  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x96E289)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-20 15:37:13  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3716    Source Network Address: 192.168.0.2    Source Port: 2405    
    Security     Audit Success   9          2008-01-20 15:37:13  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:39:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA0492E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 15:39:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA0492E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 15:39:59  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x96e289)    
    Security     Audit Success   2          2008-01-20 15:40:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA2FD48)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:40:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 15:42:40  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x96E289)     Logon Type: 10    
    Security     Audit Success   2          2008-01-20 15:50:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC9C2E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 15:50:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 16:00:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF04F9A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-20 16:00:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-20 16:07:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x10B0AB8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-20 16:07:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x10B0AB8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E29C6)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC9C2E4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x622AFA)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA2FD48)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x297F8D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4194E5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EC593)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7FA14E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF04F9A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-20 16:08:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5EC6A2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 13:36:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 452     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:36:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 13:36:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 452     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:36:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 13:36:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:36:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x182E10)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:36:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x186D4F)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 452     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:36:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x186D4F)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 13:36:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 452    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 13:36:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:37:10  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19E4DD)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3100     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:37:10  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3100    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 13:37:10  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:39:16  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B5211)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 13:39:16  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 13:39:16  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:39:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B7A2C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 13:39:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:39:49  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3844     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1253    
    Security     Audit Success   2          2008-01-21 13:39:49  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 13:39:49  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3844    Source Network Address: 192.168.0.2    Source Port: 1253    
    Security     Audit Success   9          2008-01-21 13:39:49  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:41:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3133)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3716     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1252    
    Security     Audit Success   2          2008-01-21 13:41:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3133)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 13:41:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3716    Source Network Address: 192.168.0.2    Source Port: 1252    
    Security     Audit Success   9          2008-01-21 13:41:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:43:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E92EE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 13:43:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E92EE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 13:43:50  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-21 13:44:02  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1d3133)    
    Security     Audit Success   2          2008-01-21 13:44:07  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3133)     Logon Type: 10    
    Security     Audit Success   2          2008-01-21 13:49:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x260382)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 13:49:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:50:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26BE9E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-21 13:50:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 13:50:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26BE9E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 13:59:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x388D7B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 13:59:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:00:18  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B5211)     Logon Type: 8    
    Security     Audit Success   2          2008-01-21 14:09:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4993F6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:09:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:15:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4CBFA4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 14:15:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4CBFA4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 14:19:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x50E4C1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:19:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:29:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x77FADB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:29:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:39:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DBB37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:39:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:47:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBA8023)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 14:47:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBA8023)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 14:49:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC57ECC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:49:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 14:59:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE8B044)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 14:59:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:09:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10C2840)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:09:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:19:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1308EB7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 15:19:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1308EB7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 15:19:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x133A25E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:19:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:29:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C1794)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:29:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:39:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1817C40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:39:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:49:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AB029D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:49:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 15:51:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1AFD9D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 15:51:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1AFD9D1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 15:59:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D37499)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 15:59:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:09:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F8FD8F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 16:09:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:12:39  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2058114)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2352     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:12:39  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2352    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:12:39  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:12:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x205CE97)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2104     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2593    
    Security     Audit Success   2          2008-01-21 16:12:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x205CE97)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:12:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2104    Source Network Address: 192.168.0.2    Source Port: 2593    
    Security     Audit Success   9          2008-01-21 16:12:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:12:47  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x205CE97)     Logon Type: 10    
    Security     Audit Success   2          2008-01-21 16:12:47  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-21 16:13:39  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 740    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-21 16:13:39  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 208    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-21 16:13:39  Administrator                   Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Logon GUID: -    User whose credentials were used:     Target User Name: Christoph Weber     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: bier    Target Server Info: bier    Caller Process ID: 208    Source Network Address: -    Source Port: -    
    Security     Audit Success   2          2008-01-21 16:13:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2067CBF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:13:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2067CC9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:13:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2067CC9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:13:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2067CBF)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:14:23  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BA749)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-21 16:14:27  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x207621A)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2024     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2598    
    Security     Audit Success   2          2008-01-21 16:14:27  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x207621A)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:14:27  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2024    Source Network Address: 192.168.0.2    Source Port: 2598    
    Security     Audit Success   9          2008-01-21 16:14:27  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:15:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20D7BB3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-21 16:15:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:15:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20DC524)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:15:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20DC524)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:19:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2228243)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 16:19:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:22:38  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x207621a)    
    Security     Audit Success   2          2008-01-21 16:22:44  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ba749)    
    Security     Audit Success   1          2008-01-21 16:22:55                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-21 16:23:58  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:23:58  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:23:58  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:23:58  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:23:58  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:24:04  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC8310)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 456     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:24:04  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC8310)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 16:24:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC79C5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:24:04  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 456    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:24:04  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:24:32  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE3B5C)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3104     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:24:32  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3104    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:24:32  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:25:28  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEF87A)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3420     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2676    
    Security     Audit Success   2          2008-01-21 16:25:28  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEF87A)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:25:28  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3420    Source Network Address: 192.168.0.2    Source Port: 2676    
    Security     Audit Success   9          2008-01-21 16:25:28  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:29:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13D3D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 16:29:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:31:17  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xef87a)    
    Security     Audit Success   1          2008-01-21 16:31:21                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-21 16:32:27  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:32:27  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:32:27  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:32:27  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:32:27  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:32:33  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D5E1)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:32:33  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D5E1)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 16:32:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12C3EB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:32:33  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:32:33  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:33:01  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x149A75)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3140     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:33:01  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3140    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:33:01  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:33:28  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x150E02)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3308     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2741    
    Security     Audit Success   2          2008-01-21 16:33:28  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x150E02)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:33:28  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3308    Source Network Address: 192.168.0.2    Source Port: 2741    
    Security     Audit Success   9          2008-01-21 16:33:28  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:39:42  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x150e02)    
    Security     Audit Success   1          2008-01-21 16:39:46                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-21 16:40:54  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 652     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:40:54  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:40:54  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 652     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:40:54  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:40:54  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:41:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x588D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:41:04  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5BDD1)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 652     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:41:04  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5BDD1)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 16:41:04  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 652    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:41:04  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:41:29  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x75BC8)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2868     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:41:29  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2868    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:41:29  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:42:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8421C)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3200     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2842    
    Security     Audit Success   2          2008-01-21 16:42:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8421C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:42:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3200    Source Network Address: 192.168.0.2    Source Port: 2842    
    Security     Audit Success   9          2008-01-21 16:42:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:45:43  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8421c)    
    Security     Audit Success   1          2008-01-21 16:45:51                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-21 16:46:59  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:46:59  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:46:59  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:46:59  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:46:59  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:47:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5AFF5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:47:06  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5B5DC)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:47:06  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5B5DC)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 16:47:06  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:47:06  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:47:32  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x772FE)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3180     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:47:32  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3180    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:47:32  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:49:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90D28)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 16:49:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:49:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x920C9)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3552     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2937    
    Security     Audit Success   2          2008-01-21 16:49:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x920C9)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:49:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3552    Source Network Address: 192.168.0.2    Source Port: 2937    
    Security     Audit Success   9          2008-01-21 16:49:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:52:07  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x920c9)    
    Security     Audit Success   1          2008-01-21 16:52:21                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-01-21 16:53:32  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:53:32  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:53:32  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:53:32  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:53:32  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:53:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17C1E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:53:41  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17E7E7)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:53:41  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17E7E7)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-21 16:53:41  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:53:41  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:54:05  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A9E4)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3216     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-21 16:54:05  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3216    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-21 16:54:05  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:55:02  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A70C3)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3388     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2969    
    Security     Audit Success   2          2008-01-21 16:55:02  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A70C3)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 16:55:02  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3388    Source Network Address: 192.168.0.2    Source Port: 2969    
    Security     Audit Success   9          2008-01-21 16:55:02  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:55:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A9505)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:55:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1A9505)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:56:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1BE7B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:56:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BE7BE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-21 16:56:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 16:56:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1BE7B4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:56:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1C08A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 16:56:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1C08A2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 16:59:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20F78F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 16:59:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:09:16  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1a70c3)    
    Security     Audit Success   2          2008-01-21 17:09:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2FA4D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:09:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:10:51  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A70C3)     Logon Type: 10    
    Security     Audit Success   2          2008-01-21 17:11:13  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32A373)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 216     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2991    
    Security     Audit Success   2          2008-01-21 17:11:13  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32A373)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-21 17:11:13  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 216    Source Network Address: 192.168.0.2    Source Port: 2991    
    Security     Audit Success   9          2008-01-21 17:11:13  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:16:58  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32a373)    
    Security     Audit Success   2          2008-01-21 17:17:00  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32A373)     Logon Type: 10    
    Security     Audit Success   2          2008-01-21 17:19:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3CC83F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:19:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:27:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x41FC2F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 17:27:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x41FC2F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 17:29:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x492AB9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:29:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:36:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x652D4B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 17:36:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x652D4B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 17:39:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6E4F53)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:39:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:49:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x916867)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:49:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 17:59:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAFAD21)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 17:59:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAFAD21)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 17:59:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB251D9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 17:59:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:09:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD25FB1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 18:09:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:19:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE610B5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 18:19:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:29:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEC2750)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 18:29:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:31:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xEDA578)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 18:31:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xEDA578)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:39:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF3C163)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 18:39:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:45:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BE7BE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:47:18  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF91D0A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 18:47:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF91D26)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-21 18:47:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:47:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF91D0A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:47:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF924FB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-21 18:47:29  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF924FB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:48:57  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF91D26)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:49:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFAE82B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-21 18:49:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x916867)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2FA4D2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD25FB1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20F78F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFAE82B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3CC83F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x492AB9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6E4F53)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE610B5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEC2750)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF3C163)     Logon Type: 3    
    Security     Audit Success   2          2008-01-21 18:51:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB251D9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 01:30:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 01:30:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 01:30:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x194B3F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:24  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x195CEE)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:24  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x195CEE)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-23 01:30:24  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 01:30:24  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 01:30:58  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AEC89)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3108     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 01:30:58  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3108    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 01:30:58  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:24:05  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:05  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 18:24:05  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:05  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 18:24:05  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A6CBE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:15  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AB017)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:15  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AB017)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-23 18:24:15  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 18:24:15  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:24:39  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C2A93)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3204     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:24:39  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3204    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 18:24:39  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:25:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CD21F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 18:25:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:26:28  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6E41)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3584     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1062    
    Security     Audit Success   2          2008-01-23 18:26:28  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6E41)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 18:26:28  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3584    Source Network Address: 192.168.0.2    Source Port: 1062    
    Security     Audit Success   9          2008-01-23 18:26:28  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:27:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E0E40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 18:27:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E0E40)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 18:27:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E2F5A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 18:27:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2F65)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-23 18:27:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:27:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E2F5A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 18:28:41  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F869D)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3076     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 18:28:41  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3076    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 18:28:41  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:29:01  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FCA5C)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3328     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1131    
    Security     Audit Success   2          2008-01-23 18:29:01  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FCA5C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 18:29:01  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3328    Source Network Address: 192.168.0.2    Source Port: 1131    
    Security     Audit Success   9          2008-01-23 18:29:01  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:30:35  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FCA5C)     Logon Type: 10    
    Security     Audit Success   2          2008-01-23 18:35:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26604F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 18:35:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:44:55  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1d6e41)    
    Security     Audit Success   2          2008-01-23 18:45:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x36C2E3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 18:45:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:46:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2F65)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 18:47:39  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6E41)     Logon Type: 10    
    Security     Audit Success   2          2008-01-23 18:49:45  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F869D)     Logon Type: 8    
    Security     Audit Success   2          2008-01-23 18:55:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3EC0BE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 18:55:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 18:59:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x415179)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 18:59:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x415179)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 19:05:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61DF74)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:05:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:15:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x83D3F6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:15:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:25:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA7ECC1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:25:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:31:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBB05D0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 19:31:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBB05D0)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 19:32:05  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD661A)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1764     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1512    
    Security     Audit Success   2          2008-01-23 19:32:05  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD661A)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 19:32:05  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1764    Source Network Address: 192.168.0.2    Source Port: 1512    
    Security     Audit Success   9          2008-01-23 19:32:05  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:35:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC7F555)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:35:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:40:04  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xbd661a)    
    Security     Audit Success   2          2008-01-23 19:40:05  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD661A)     Logon Type: 10    
    Security     Audit Success   2          2008-01-23 19:40:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA2A50)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 712     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1567    
    Security     Audit Success   2          2008-01-23 19:40:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA2A50)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 19:40:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 712    Source Network Address: 192.168.0.2    Source Port: 1567    
    Security     Audit Success   9          2008-01-23 19:40:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:42:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE02CD2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-23 19:42:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:42:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE05078)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 19:42:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE05078)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 19:45:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEDCCD7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:45:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:49:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF67760)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 19:49:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF67760)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 19:55:06  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xda2a50)    
    Security     Audit Success   2          2008-01-23 19:55:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x109E61D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 19:55:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 19:56:41  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA2A50)     Logon Type: 10    
    Security     Audit Success   2          2008-01-23 20:03:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12CC1B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 20:03:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12CC1B2)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:05:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1339925)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 20:05:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:15:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1564426)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 20:15:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1564426)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:15:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1576981)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 20:15:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:28:21  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:21  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 20:28:21  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:21  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 20:28:21  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:28  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17FCC7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x180F0B)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x180F0B)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-23 20:28:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 20:28:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:28:55  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19B4FD)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3136     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-23 20:28:55  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3136    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-23 20:28:55  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:30:06  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8571)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3440     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1903    
    Security     Audit Success   2          2008-01-23 20:30:06  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8571)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-23 20:30:06  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3440    Source Network Address: 192.168.0.2    Source Port: 1903    
    Security     Audit Success   9          2008-01-23 20:30:06  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:35:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1F550C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 20:35:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1F550C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:36:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x209987)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 20:36:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:45:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A7563)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 20:45:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A7A7E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-23 20:45:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:45:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A7563)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:45:30  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A7A7E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:45:33  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1a8571)    
    Security     Audit Success   2          2008-01-23 20:45:36  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8571)     Logon Type: 10    
    Security     Audit Success   2          2008-01-23 20:46:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D9370)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 20:46:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:47:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F1970)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-23 20:47:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 20:47:51  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F1970)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 20:56:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x375913)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 20:56:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 21:06:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x43FE37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 21:06:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 21:07:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x453383)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-23 21:07:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x453383)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:16:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7102DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 21:16:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 21:26:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x970C77)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-23 21:26:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x43FE37)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x375913)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x209987)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x970C77)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7102DE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-23 21:36:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D9370)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 08:29:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-24 08:29:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-24 08:29:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:22  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x187B57)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:22  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x187B57)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-24 08:29:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x186D1C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:22  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-24 08:29:22  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 08:29:48  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A391C)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3096     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-24 08:29:48  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3096    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-24 08:29:48  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 08:31:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F40)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3412     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1192    
    Security     Audit Success   2          2008-01-24 08:31:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F40)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-24 08:31:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3412    Source Network Address: 192.168.0.2    Source Port: 1192    
    Security     Audit Success   9          2008-01-24 08:31:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 08:36:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F6E51)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-24 08:36:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 08:36:43  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1b0f40)    
    Security     Audit Success   2          2008-01-24 08:36:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F6E51)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 08:37:42  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F40)     Logon Type: 10    
    Security     Audit Success   2          2008-01-24 23:23:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB43D18D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-24 23:23:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 23:25:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB495F2A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-24 23:25:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB495F2A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 23:28:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB53AAB5)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3292     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1115    
    Security     Audit Success   2          2008-01-24 23:28:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB53AAB5)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-24 23:28:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3292    Source Network Address: 192.168.0.2    Source Port: 1115    
    Security     Audit Success   9          2008-01-24 23:28:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 23:32:05  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xb53aab5)    
    Security     Audit Success   2          2008-01-24 23:33:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB5EDA9E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-24 23:33:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 23:34:18  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB53AAB5)     Logon Type: 10    
    Security     Audit Success   2          2008-01-24 23:34:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB63D2A4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-24 23:34:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-24 23:34:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB63D35C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-24 23:34:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB63D35C)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 23:36:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB63D2A4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 23:36:20  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB5EDA9E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 23:36:20  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB43D18D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-24 23:50:53  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A391C)     Logon Type: 8    
    Security     Audit Success   2          2008-01-25 08:23:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B3DA67)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-25 08:23:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-25 08:24:33  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B71A2B)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3264     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1062    
    Security     Audit Success   2          2008-01-25 08:24:33  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B71A2B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-25 08:24:33  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3264    Source Network Address: 192.168.0.2    Source Port: 1062    
    Security     Audit Success   9          2008-01-25 08:24:33  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-25 08:24:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11B7BA63)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-25 08:24:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11B7BA63)     Logon Type: 3    
    Security     Audit Success   2          2008-01-25 08:25:52  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B8AC65)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3108     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-25 08:25:52  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3108    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-25 08:25:52  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-25 08:26:04  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11b71a2b)    
    Security     Audit Success   2          2008-01-25 08:26:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B3DA67)     Logon Type: 3    
    Security     Audit Success   2          2008-01-25 08:30:03  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B71A2B)     Logon Type: 10    
    Security     Audit Success   2          2008-01-25 08:46:53  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B8AC65)     Logon Type: 8    
    Security     Audit Success   2          2008-01-27 17:21:00  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 17:21:00  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 17:21:00  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 17:21:00  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 17:21:00  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 17:21:07  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1624A0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 17:21:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x164A3F)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 17:21:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x164A3F)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-27 17:21:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 17:21:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:21:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17B5B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 17:21:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:22:54  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18BCB2)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3164     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1049    
    Security     Audit Success   2          2008-01-27 17:22:54  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18BCB2)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 17:22:54  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3164    Source Network Address: 192.168.0.2    Source Port: 1049    
    Security     Audit Success   9          2008-01-27 17:22:54  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:23:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18EC2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 17:23:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:23:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1926D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 17:23:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1926D1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:23:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18EC2E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:26:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B9328)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 17:26:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B9332)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 17:26:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:26:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B9328)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:28:19  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18bcb2)    
    Security     Audit Success   2          2008-01-27 17:28:31  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18BCB2)     Logon Type: 10    
    Security     Audit Success   2          2008-01-27 17:30:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B9332)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:30:59  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17B5B7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:32:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x201BA3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 17:32:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:32:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x201F1F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 17:32:12  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x201F1F)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:32:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20353E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 17:32:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:33:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2139BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 17:33:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2139BA)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 17:42:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27927A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 17:42:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 17:52:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F236A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 17:52:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:02:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x34E96E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:02:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:05:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x370422)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:05:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x370422)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:07:25  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x381473)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2720     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1122    
    Security     Audit Success   2          2008-01-27 18:07:25  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x381473)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:07:25  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2720    Source Network Address: 192.168.0.2    Source Port: 1122    
    Security     Audit Success   9          2008-01-27 18:07:25  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:11:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3BE4A9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:11:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3BE4A9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:12:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3C93E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:12:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:18:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:18:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:18:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:20  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C0F37)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:20  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C0F37)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-27 18:18:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1C0705)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:20  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 18:18:20  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:18:38  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D90AE)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 2896     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:18:38  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2896    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 18:18:38  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:19:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2D36)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3264     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1260    
    Security     Audit Success   2          2008-01-27 18:19:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2D36)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:19:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3264    Source Network Address: 192.168.0.2    Source Port: 1260    
    Security     Audit Success   9          2008-01-27 18:19:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:22:14  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2D36)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-27 18:22:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2103B5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:22:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:22:26  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x211E42)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2012     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1325    
    Security     Audit Success   2          2008-01-27 18:22:26  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x211E42)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:22:26  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2012    Source Network Address: 192.168.0.2    Source Port: 1325    
    Security     Audit Success   9          2008-01-27 18:22:26  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:24:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x239595)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 18:24:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:24:25  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x239595)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:24:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24298A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 18:24:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:24:55  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24298A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:25:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A8D9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 18:25:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:26:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A8D9)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:32:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B968B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:32:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:37:14  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:37:14  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:37:14  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:37:14  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:37:14  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:37:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18F721)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:37:23  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x191ED0)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:37:23  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x191ED0)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-27 18:37:23  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 18:37:23  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:37:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ABDD3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-27 18:37:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:37:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1ACE89)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:37:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1ACE89)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:37:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1ADD60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:38:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1ADD60)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:38:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1AE1E1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:38:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1AE1E1)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:38:19  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F8A)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3140     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1598    
    Security     Audit Success   2          2008-01-27 18:38:19  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F8A)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:38:19  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3140    Source Network Address: 192.168.0.2    Source Port: 1598    
    Security     Audit Success   9          2008-01-27 18:38:19  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:42:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EC1D6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:42:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:51:20  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x269DE1)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3668     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 18:51:20  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3668    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 18:51:20  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:51:36  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26D313)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3972     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1974    
    Security     Audit Success   2          2008-01-27 18:51:36  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26D313)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 18:51:36  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3972    Source Network Address: 192.168.0.2    Source Port: 1974    
    Security     Audit Success   9          2008-01-27 18:51:36  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:52:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2788F0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 18:52:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 18:52:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27F6CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:53:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27F6CA)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:54:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x28A07E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:54:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x28A07E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 18:54:45  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26D313)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-27 18:59:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2C555A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 18:59:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2C555A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:00:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2D9A53)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:00:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2D9A53)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:00:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2DAC50)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:00:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2DAC50)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:01:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E9682)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:01:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E9682)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:01:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E96C4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:01:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E96C4)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:02:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30BEDF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 19:02:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:03:41  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1b0f8a)    
    Security     Audit Success   2          2008-01-27 19:03:43  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0F8A)     Logon Type: 10    
    Security     Audit Success   2          2008-01-27 19:10:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x39B76B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:10:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x39B76B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:34:34  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:34:34  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 19:34:34  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:34:34  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 19:34:34  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:34:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A316F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:34:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A5429)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:34:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A5429)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-27 19:34:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 19:34:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:42:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21443B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 19:42:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21443B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 19:43:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22D551)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 19:43:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:51:08  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BBC63)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3916     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 19:51:08  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3916    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 19:51:08  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:51:22  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C23C8)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 4080     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2569    
    Security     Audit Success   2          2008-01-27 19:51:22  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C23C8)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 19:51:22  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 4080    Source Network Address: 192.168.0.2    Source Port: 2569    
    Security     Audit Success   9          2008-01-27 19:51:22  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:53:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F6F02)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 19:53:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 19:59:34  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C23C8)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-27 20:03:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x39B034)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 20:03:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:12:17  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BBC63)     Logon Type: 8    
    Security     Audit Success   2          2008-01-27 20:12:31  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x405947)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 608     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 20:12:31  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 608    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-27 20:12:31  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:12:54  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x408E01)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1608     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2587    
    Security     Audit Success   2          2008-01-27 20:12:54  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x408E01)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-27 20:12:54  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1608    Source Network Address: 192.168.0.2    Source Port: 2587    
    Security     Audit Success   9          2008-01-27 20:12:54  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:12:56  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C23C8)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-27 20:12:57  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x408E01)     Logon Type: 10    
    Security     Audit Success   2          2008-01-27 20:13:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x40CF18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 20:13:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:14:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4106BB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 20:14:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4106BB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 20:23:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6C2B70)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 20:23:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:33:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8FCC0E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-27 20:33:34  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x405947)     Logon Type: 8    
    Security     Audit Success   9          2008-01-27 20:33:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:40:36  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C23C8)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-27 20:43:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA1DCCB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 20:43:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 20:46:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA27779)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-27 20:46:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA27779)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 20:53:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAB734A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 20:53:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 21:03:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBC45B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 21:03:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 21:13:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE1ACE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-27 21:13:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6C2B70)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE1ACE7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x39B034)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22D551)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xAB734A)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8FCC0E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA1DCCB)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F6F02)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBC45B7)     Logon Type: 3    
    Security     Audit Success   2          2008-01-27 21:14:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x40CF18)     Logon Type: 3    
    Security     Audit Success   2          2008-01-28 08:21:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DDB548)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-28 08:21:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-28 08:22:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DDB548)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 18:20:03  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:20:03  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 18:20:03  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:20:03  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 18:20:03  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:20:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0D64)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:20:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0D64)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-30 18:20:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B05CF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:20:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-30 18:20:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:21:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6A4C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 18:21:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:22:35  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E0B0E)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3372     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 18:22:35  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3372    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-30 18:22:35  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:23:08  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E4656)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3524     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1098    
    Security     Audit Success   2          2008-01-30 18:23:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E4656)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 18:23:08  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3524    Source Network Address: 192.168.0.2    Source Port: 1098    
    Security     Audit Success   9          2008-01-30 18:23:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:23:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E5C28)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 18:23:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E5C28)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 18:31:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22680B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 18:31:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:39:24  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27B2A5)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 412     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1150    
    Security     Audit Success   2          2008-01-30 18:39:24  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27B2A5)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 18:39:24  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 412    Source Network Address: 192.168.0.2    Source Port: 1150    
    Security     Audit Success   9          2008-01-30 18:39:24  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:41:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A0368)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 18:41:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:43:39  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E0B0E)     Logon Type: 8    
    Security     Audit Success   2          2008-01-30 18:51:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x44064E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 18:51:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 18:55:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x49246E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 18:55:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x49246E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 19:01:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4FCB18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 19:01:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:04:52  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E4656)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-30 19:11:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5987D9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 19:11:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:16:58  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27b2a5)    
    Security     Audit Success   2          2008-01-30 19:17:04  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x27B2A5)     Logon Type: 10    
    Security     Audit Success   2          2008-01-30 19:17:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x65987B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-30 19:17:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:17:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x667672)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 19:17:29  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x667672)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 19:17:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x65987B)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 19:21:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9C2E13)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 19:21:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:27:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA64BD4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 19:27:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA64BD4)     Logon Type: 3    
    Security     Audit Success   9          2008-01-30 19:31:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:31:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBF85F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:30  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:30  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 19:39:30  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:30  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 19:39:30  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19691C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:39  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1988D6)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 19:39:39  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1988D6)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-30 19:39:39  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-30 19:39:39  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:41:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C6387)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 19:41:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:51:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B2DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 19:51:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 19:59:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2F498D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 19:59:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2F498D)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:01:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32DA80)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-01-30 20:01:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:02:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x33CED5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-30 20:02:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:02:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x33D20E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-01-30 20:02:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x33D20E)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:02:51  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3449F3)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 704     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:02:51  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 704    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-30 20:02:51  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:03:13  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x348B44)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1616     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1940    
    Security     Audit Success   2          2008-01-30 20:03:13  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x348B44)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 20:03:13  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1616    Source Network Address: 192.168.0.2    Source Port: 1940    
    Security     Audit Success   9          2008-01-30 20:03:13  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:03:24  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x348B44)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-01-30 20:03:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x350883)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-30 20:03:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:04:31  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x33CED5)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:04:32  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x350883)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:04:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x35CBD8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-30 20:04:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:05:00  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x35CBD8)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:05:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x367125)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-01-30 20:05:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-30 20:06:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C6387)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:06:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B2DE)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:06:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x32DA80)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:06:52  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x367125)     Logon Type: 3    
    Security     Audit Success   2          2008-01-30 20:24:00  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3449F3)     Logon Type: 8    
    Security     Audit Success   2          2008-01-30 20:52:12  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:52:12  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 20:52:12  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:52:12  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-30 20:52:12  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:52:19  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B10FF)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:52:19  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B10FF)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-30 20:52:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B0AD8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-30 20:52:19  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-30 20:52:19  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-01-31 08:18:35  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-31 08:18:35  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-31 08:18:35  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-31 08:18:35  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-01-31 08:18:35  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-31 08:18:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B9EC7)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-31 08:18:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B9EC7)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-01-31 08:18:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B9720)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-01-31 08:18:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-01-31 08:18:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:49:57  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:49:57  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 17:49:57  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:49:57  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 17:49:57  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:50:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A284A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:50:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A49E3)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:50:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A49E3)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-01 17:50:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-01 17:50:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:50:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C0B60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 17:50:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:52:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D4DC5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 17:52:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D4DC5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 17:56:18  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2091F5)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 3624     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 17:56:18  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3624    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-01 17:56:18  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:56:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20BC12)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 17:56:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20BC1C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-01 17:56:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:57:01  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20BC12)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 17:57:49  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210F90)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3992     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1122    
    Security     Audit Success   2          2008-02-01 17:57:49  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210F90)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 17:57:49  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3992    Source Network Address: 192.168.0.2    Source Port: 1122    
    Security     Audit Success   9          2008-02-01 17:57:49  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:58:04  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2145C3)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1088     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1124    
    Security     Audit Success   2          2008-02-01 17:58:04  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2145C3)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 17:58:04  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1088    Source Network Address: 192.168.0.2    Source Port: 1124    
    Security     Audit Success   9          2008-02-01 17:58:04  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 17:58:29  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210F90)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-02-01 17:58:39  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210F90)     Logon Type: 10    
    Security     Audit Success   2          2008-02-01 17:59:37  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2145c3)    
    Security     Audit Success   2          2008-02-01 18:00:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2335D7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:00:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:04:04  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2145C3)     Logon Type: 10    
    Security     Audit Success   2          2008-02-01 18:10:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x259B4F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:10:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:18:22  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2091F5)     Logon Type: 8    
    Security     Audit Success   2          2008-02-01 18:20:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B0ECB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:20:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:24:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2C82A3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 18:24:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2C82A3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 18:30:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EAE30)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:30:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:40:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x353532)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 18:40:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x353532)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 18:40:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x366C33)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:40:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:50:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61882F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 18:50:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 18:56:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7508A0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 18:56:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7508A0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:00:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x89ABD2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:00:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:10:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB3A1EA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:10:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:20:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDF7961)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:20:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:28:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xFE3CDE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 19:28:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xFE3CDE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:30:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x107D3B6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:30:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:40:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1324193)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:40:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:42:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x135E702)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 19:42:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x135E702)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:50:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C14E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-01 19:50:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-01 19:50:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15D6E74)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-01 19:51:07  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x15D6E74)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61882F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1324193)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDF7961)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x259B4F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x366C33)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EAE30)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2335D7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B0ECB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C14E7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB3A1EA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C0B60)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x89ABD2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x107D3B6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 19:55:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20BC1C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-01 21:51:23  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 21:51:23  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 21:51:23  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 21:51:23  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-01 21:51:23  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 21:51:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x175F8F)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 21:51:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x175F8F)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-01 21:51:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1756AC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-01 21:51:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-01 21:51:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:04:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB80D1ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:04:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:05:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB83E0DD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 11:05:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB83E0DD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 11:08:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB90E4D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 11:08:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB90E4DD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-02 11:08:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:08:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB90E4D3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 11:14:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBABF202)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:14:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:24:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD2E942)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:24:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:34:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBFD0D4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:34:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:37:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC0B3B1F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 11:37:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC0B3B1F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 11:44:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC2566F8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:44:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:54:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC438929)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 11:54:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 11:55:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC485ED3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 11:55:44  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC485ED3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 12:04:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5BE4E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:04:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 12:09:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC70A8A8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 12:09:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC70A8A8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 12:14:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC7E3B2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:14:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 12:24:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCA1B664)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:24:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 12:26:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCA8CDD3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 12:26:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCA8CDD3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 12:26:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB90E4DD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 12:34:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCC95718)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:34:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 12:41:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCE1522D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 12:41:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCE1522D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 12:44:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEB9B43)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:44:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 12:54:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD12FDE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 12:54:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:04:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3881E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:04:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:13:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD517FD5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 13:13:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD517FD5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 13:14:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD51C09A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:14:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:24:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD70A663)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:24:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:34:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD93A0FB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:34:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:44:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDB22777)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:44:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 13:45:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDB68F09)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 13:45:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDB68F09)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 13:54:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDD47423)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 13:54:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:04:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDF9F583)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:04:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:14:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE1AECF0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:14:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:17:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE253E64)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 14:17:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE253E64)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 14:24:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE3ACA07)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:24:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:34:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE5BDE0A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:34:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:44:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE841F33)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:44:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 14:49:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE97BC8C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 14:49:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE97BC8C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 14:54:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEAE27D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 14:54:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:04:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xECABF80)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:04:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:14:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEEB4284)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:14:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:21:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF08E961)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 15:21:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF08E961)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 15:24:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF11E5CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:24:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:34:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF3C36CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:34:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:44:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF632E69)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:44:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 15:53:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF8154DA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 15:53:43  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF8154DA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 15:54:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF85B385)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 15:54:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:04:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFABC845)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:04:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:14:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFCD9DF6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:14:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:24:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFDE51BC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:24:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:25:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xFE091E0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 16:25:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xFE091E0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 16:34:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFF0F7F9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:34:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:44:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1006331E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:44:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:54:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10228D12)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 16:54:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 16:57:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x102BCDE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 16:57:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x102BCDE7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:04:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x103ED1B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 17:04:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDB22777)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC438929)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEEB4284)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEAE27D1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBFD0D4D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF11E5CD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBD2E942)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x103ED1B7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD51C09A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB80D1ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE5BDE0A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF85B385)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFF0F7F9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3881E9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEB9B43)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCC95718)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE3ACA07)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE1AECF0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBABF202)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC7E3B2E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD70A663)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFCD9DF6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDF9F583)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE841F33)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDD47423)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF632E69)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10228D12)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD93A0FB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD12FDE7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC2566F8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1006331E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCA1B664)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFABC845)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFDE51BC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF3C36CD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xECABF80)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:06:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5BE4E4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 17:29:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x10914E62)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 17:29:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x10914E62)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 18:01:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x10EE7458)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 18:01:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x10EE7458)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 18:33:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1146DA92)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 18:33:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1146DA92)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 19:05:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11AD8FFF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 19:05:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11AD8FFF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 19:37:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11FCF43E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 19:37:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11FCF43E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 20:09:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x125E08DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 20:09:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x125E08DE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 20:41:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12D58BDB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 20:41:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12D58BDB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:13:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x135ABFA0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 21:13:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x135ABFA0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:32:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A60E5B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-02 21:32:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 21:32:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x13A60EE1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 21:32:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x13A60EE1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:33:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x13A65F3E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 21:33:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x13A65F3E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:33:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x13A65F5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-02 21:33:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x13A65F5F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:34:04  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A60E5B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-02 21:37:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13B4ED5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-02 21:37:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-02 21:38:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13B4ED5F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 10:42:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C6D782F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 10:42:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 10:44:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1C6DAE86)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 10:44:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1C6DAE86)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 10:52:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C80B366)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 10:52:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:02:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CA5EB67)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:02:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:12:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CCB588A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:12:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:16:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1CDF5231)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 11:16:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1CDF5231)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 11:22:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CF1820C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:22:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:32:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D10CBAE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:32:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:42:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D399B40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:42:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:48:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D520BCD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 11:48:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D520BCD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 11:52:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6259F0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 11:52:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 11:58:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D77611D)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2376     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1686    
    Security     Audit Success   2          2008-02-03 11:58:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D77611D)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-03 11:58:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2376    Source Network Address: 192.168.0.2    Source Port: 1686    
    Security     Audit Success   9          2008-02-03 11:58:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:02:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7C3662)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:02:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:02:41  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1d77611d)    
    Security     Audit Success   2          2008-02-03 12:02:44  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D77611D)     Logon Type: 10    
    Security     Audit Success   2          2008-02-03 12:05:05  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7D3E53)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3064     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1696    
    Security     Audit Success   2          2008-02-03 12:05:05  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7D3E53)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-03 12:05:05  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3064    Source Network Address: 192.168.0.2    Source Port: 1696    
    Security     Audit Success   9          2008-02-03 12:05:05  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:07:49  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1d7d3e53)    
    Security     Audit Success   2          2008-02-03 12:11:47  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7D3E53)     Logon Type: 10    
    Security     Audit Success   2          2008-02-03 12:12:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D9105A4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:12:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:18:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DA88E3E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-03 12:18:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:18:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DA88F0C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:18:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DA88F0C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:19:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DAA79BB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:19:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DAA79BB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:19:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DAA7A5E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:19:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DAA7A5E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:20:31  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DAC8E9F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:20:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DAC8E9F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:20:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DAC9010)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:20:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DAC9010)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:20:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1DAC90FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:20:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1DAC90FA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:22:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DB0ED4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:22:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:32:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DC660DB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:32:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:42:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DEB7F5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:42:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:52:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E0D740D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 12:52:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 12:52:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E0E0419)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 12:52:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E0E0419)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:53:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DA88E3E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E0D740D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D10CBAE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CCB588A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D399B40)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CA5EB67)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C80B366)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C6D782F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D9105A4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7C3662)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D6259F0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DC660DB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DEB7F5F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DB0ED4D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 12:57:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CF1820C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 15:55:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FC7C441)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 15:55:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 15:57:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FCB0013)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 15:57:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FCB0013)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 16:05:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FE65427)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:05:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 16:15:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x200631A5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:15:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 16:25:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20227769)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:25:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 16:29:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x202C86A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 16:29:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x202C86A2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 16:35:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20430084)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:35:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 16:45:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x205E7E44)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:45:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 16:55:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2081B947)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 16:55:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:01:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20979AED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 17:01:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20979AED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 17:05:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20A83B1E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:05:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:15:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20CA0D3C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:15:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:21:44  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20D92EB4)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2280     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1579    
    Security     Audit Success   2          2008-02-03 17:21:44  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20D92EB4)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-03 17:21:44  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2280    Source Network Address: 192.168.0.2    Source Port: 1579    
    Security     Audit Success   9          2008-02-03 17:21:44  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:23:47  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20d92eb4)    
    Security     Audit Success   2          2008-02-03 17:23:49  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20D92EB4)     Logon Type: 10    
    Security     Audit Success   2          2008-02-03 17:25:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20E69BAE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:25:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:33:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20FF18FB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 17:33:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20FF18FB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 17:35:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2105F035)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:35:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:45:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212ADC1B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:45:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 17:55:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x214C81D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 17:55:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:05:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21694A0C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 18:05:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21694A0C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 18:05:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x216C6DEC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:05:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:15:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x218D3B11)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:15:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:25:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21B09BB9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:25:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:35:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21D52C0F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:35:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:37:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21D8B24B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 18:37:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21D8B24B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 18:45:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21F3288D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:45:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 18:55:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22135D22)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 18:55:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:05:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22365E73)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:05:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:09:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x223D3167)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 19:09:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x223D3167)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 19:15:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2252129E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:15:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:26:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2267940C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:26:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:36:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x228EA3B5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:36:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:41:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x229D114E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 19:41:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x229D114E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 19:46:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22A953ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:46:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 19:56:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22C54D98)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 19:56:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 20:06:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22DEF85A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 20:06:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 20:13:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22F9247A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-03 20:13:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22F9247A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:16:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22FF7156)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 20:16:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 20:26:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x231F340E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-03 20:26:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22135D22)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x205E7E44)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20A83B1E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22C54D98)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22A953ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20227769)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2252129E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20CA0D3C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FC7C441)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21D52C0F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20E69BAE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x216C6DEC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22DEF85A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x214C81D2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212ADC1B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x228EA3B5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22FF7156)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x218D3B11)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x200631A5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20430084)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FE65427)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21B09BB9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21F3288D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x231F340E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22365E73)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2105F035)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2267940C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-03 20:34:15  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2081B947)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 09:33:05  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 09:33:05  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 09:33:05  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 09:33:05  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 09:33:05  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 09:33:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B44E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 09:33:15  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B4FCB)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 09:33:15  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B4FCB)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 09:33:15  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 09:33:15  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:17:41  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:17:41  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:17:41  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:17:41  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:17:41  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:17:48  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16CF5E)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:17:48  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16CF5E)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 18:17:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x16C36E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:17:48  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 18:17:48  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:18:17  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x189200)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2936     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1129    
    Security     Audit Success   2          2008-02-06 18:18:17  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x189200)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:18:17  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2936    Source Network Address: 192.168.0.2    Source Port: 1129    
    Security     Audit Success   9          2008-02-06 18:18:17  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:25:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28EAC0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-06 18:25:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:26:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2900F9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 18:26:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2900F9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 18:27:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x307035)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 18:27:42  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x307035)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 18:28:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x31F7DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 18:28:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:29:55  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3948CF)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:29:55  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3948CF)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 18:29:55  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 18:29:55  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:33:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28EAC0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 18:33:25  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16CF5E)     Logon Type: 5    
    Security     Audit Success   2          2008-02-06 18:34:59  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x189200)    
    Security     Audit Success   2          2008-02-06 18:35:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4B0ACF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 18:35:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B0AD9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-06 18:35:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:35:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4B0ACF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 18:36:48  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D2CA6)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3544     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1188    
    Security     Audit Success   2          2008-02-06 18:36:48  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D2CA6)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:36:48  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3544    Source Network Address: 192.168.0.2    Source Port: 1188    
    Security     Audit Success   9          2008-02-06 18:36:48  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:38:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EEE73)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 18:38:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:40:32  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x189200)     Logon Type: 10    
    Security     Audit Success   2          2008-02-06 18:46:18  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4d2ca6)    
    Security     Audit Success   2          2008-02-06 18:47:00  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x581CD1)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 308     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 18:47:00  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 308    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 18:47:00  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:47:08  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587226)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2132     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1233    
    Security     Audit Success   2          2008-02-06 18:47:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587226)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:47:08  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2132    Source Network Address: 192.168.0.2    Source Port: 1233    
    Security     Audit Success   9          2008-02-06 18:47:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:47:48  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587226)     Session Name: RDP-Tcp#3     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-02-06 18:48:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61953D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 18:48:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:49:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6D18BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 18:49:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6D18BA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 18:49:34  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6D7872)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 2192     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1263    
    Security     Audit Success   2          2008-02-06 18:49:34  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6D7872)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 18:49:34  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 2192    Source Network Address: 192.168.0.2    Source Port: 1263    
    Security     Audit Success   9          2008-02-06 18:49:34  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:49:48  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587226)     Logon Type: 10    
    Security     Audit Success   2          2008-02-06 18:54:49  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D2CA6)     Logon Type: 10    
    Security     Audit Success   2          2008-02-06 18:58:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x944DF6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 18:58:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 18:59:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9C0673)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 18:59:42  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9C0673)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 19:03:34  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6d7872)    
    Security     Audit Success   2          2008-02-06 19:03:36  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6D7872)     Logon Type: 10    
    Security     Audit Success   2          2008-02-06 19:08:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCFC9E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 19:08:08  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x581CD1)     Logon Type: 8    
    Security     Audit Success   9          2008-02-06 19:08:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 19:17:19  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFE5616)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 1704     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 19:17:19  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1704    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 19:17:19  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 19:17:24  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFE6C87)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1860     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1517    
    Security     Audit Success   2          2008-02-06 19:17:24  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFE6C87)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 19:17:24  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1860    Source Network Address: 192.168.0.2    Source Port: 1517    
    Security     Audit Success   9          2008-02-06 19:17:24  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 19:18:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x100D8A6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 19:18:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 19:22:27  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFE6C87)     Session Name: RDP-Tcp#5     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-02-06 19:23:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11DBD7A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 19:23:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11DBD7A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 19:23:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11DC828)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 19:23:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11DC828)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 19:28:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1445469)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 19:28:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 19:31:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x16E53CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 19:31:42  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x16E53CA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 19:38:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B0AD9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 19:38:22  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFE5616)     Logon Type: 8    
    Security     Audit Success   2          2008-02-06 20:11:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 448     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:11:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 20:11:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 448     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:11:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 20:11:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:11:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x228C0B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:11:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B608)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 448     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:11:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B608)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 20:11:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 448    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 20:11:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 20:18:58  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 512     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:18:58  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 20:18:58  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 512     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:18:58  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 20:18:58  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:19:04  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ACA5D)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 512     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:19:04  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ACA5D)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 20:19:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1AC489)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 20:19:04  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 512    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 20:19:04  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 20:21:12  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DACB7)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3308     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2133    
    Security     Audit Success   2          2008-02-06 20:21:12  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DACB7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 20:21:12  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3308    Source Network Address: 192.168.0.2    Source Port: 2133    
    Security     Audit Success   9          2008-02-06 20:21:12  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 20:22:17  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1dacb7)    
    Security     Audit Success   2          2008-02-06 20:23:23  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DACB7)     Logon Type: 10    
    Security     Audit Success   2          2008-02-06 20:24:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x202D2A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-06 20:24:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 20:24:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2034BB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 20:24:43  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2034BB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 21:04:23  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 520     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 21:04:23  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 21:04:23  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 520     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 21:04:23  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-06 21:04:23  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 21:04:29  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D0B2E)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 520     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 21:04:29  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D0B2E)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-06 21:04:29  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D051F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-06 21:04:29  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 520    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-06 21:04:29  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 21:08:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21399F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-06 21:08:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21399F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 21:14:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24E7EC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 21:14:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 21:24:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x348447)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 21:24:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 21:34:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5F1014)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-06 21:34:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-06 21:39:57  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24E7EC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 21:39:57  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5F1014)     Logon Type: 3    
    Security     Audit Success   2          2008-02-06 21:39:57  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x348447)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 18:12:49  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-07 18:12:49  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-07 18:12:49  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-07 18:12:49  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-07 18:12:49  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-07 18:12:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B983C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-07 18:12:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BBA84)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-07 18:12:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BBA84)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-07 18:12:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-07 18:12:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-07 18:13:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D5116)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 18:13:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D5116)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 18:44:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x36B9B8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 18:44:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x36B9B8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 19:16:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA8656A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 19:16:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA8656A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 19:47:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x122C920)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 19:47:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x122C920)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 20:19:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15AB3FC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 20:19:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x15AB3FC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 20:51:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18E0CF9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 20:51:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x18E0CF9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 21:23:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1F242CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 21:23:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1F242CA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 21:49:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1F686DA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 21:49:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F686E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-07 21:49:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-07 21:49:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1F686DA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 21:55:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x210BF14)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 21:55:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x210BF14)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:05:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22A137A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:05:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22A137A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:05:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22A190A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:05:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22A190A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:05:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22A1DFB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:05:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22A1DFB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:14:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x255C40F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:14:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x255C40F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:14:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x255C41D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:14:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x255C41D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:27:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x262C948)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:27:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x262C948)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:28:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F686E4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-07 22:59:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x28EC239)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-07 22:59:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x28EC239)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 12:01:45  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 12:01:45  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-09 12:01:45  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 12:01:45  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-09 12:01:45  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 12:01:51  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3A01)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 12:01:51  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3A01)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-09 12:01:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D2BC0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 12:01:51  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-09 12:01:51  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-09 12:06:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21BCA9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 12:06:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21BCA9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 12:38:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x495470)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 12:38:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x495470)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:11:24  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 13:11:24  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-09 13:11:24  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 13:11:24  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-09 13:11:24  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 13:11:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B35F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 13:11:34  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B69C2)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-09 13:11:34  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B69C2)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-09 13:11:34  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-09 13:11:34  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-09 13:12:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D2446)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-09 13:12:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-09 13:12:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D3301)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:12:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D3301)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:18:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21AA07)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:18:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21AA07)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:18:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21B645)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:19:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21B645)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:19:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x21F375)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:19:29  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x21F375)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:33:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2B89AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:33:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2B89AE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:33:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2BA63E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:33:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2BA63E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:33:33  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D2446)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 13:42:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3154D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 13:42:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3154D4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 14:14:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAA315A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 14:14:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAA315A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 14:46:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDBCE04)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 14:46:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDBCE04)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 15:18:31  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1483F1A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 15:18:31  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1483F1A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 15:50:27  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x184091A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 15:50:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x184091A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 16:22:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E4B009)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 16:22:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E4B009)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 16:54:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x22C381E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 16:54:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x22C381E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 17:25:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2616ECA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 17:25:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2616ECA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 17:57:44  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2DBE51E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 17:57:44  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2DBE51E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 18:29:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x34E7D7D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 18:29:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x34E7D7D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 19:01:28  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x36091DF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 19:01:28  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x36091DF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 19:33:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3D0B9AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 19:33:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3D0B9AE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 20:05:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3FD6B90)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 20:05:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3FD6B90)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 20:37:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x467C26E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 20:37:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x467C26E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 21:09:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4A4BA85)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 21:09:09  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4A4BA85)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 21:10:05  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A4D647)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3008     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3363    
    Security     Audit Success   2          2008-02-09 21:10:05  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A4D647)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-09 21:10:05  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3008    Source Network Address: 192.168.0.2    Source Port: 3363    
    Security     Audit Success   9          2008-02-09 21:10:05  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-09 21:11:31  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4a4d647)    
    Security     Audit Success   2          2008-02-09 21:15:50  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A4D647)     Logon Type: 10    
    Security     Audit Success   2          2008-02-09 21:41:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5257F9C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 21:41:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5257F9C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 22:13:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x566A214)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 22:13:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x566A214)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 22:44:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5D6F2D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 22:44:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5D6F2D2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 23:03:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6178110)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 23:03:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x617811A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 23:03:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x617811A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 23:03:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x617815A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-09 23:03:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   9          2008-02-09 23:03:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-09 23:03:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6178110)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 23:03:56  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x617815A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-09 23:16:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x619DC2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-09 23:16:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x619DC2E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 10:31:24  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 10:31:24  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 10:31:24  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 10:31:24  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 10:31:24  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 10:31:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16C5FA)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 10:31:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16C5FA)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-10 10:31:31  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x16B646)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 10:31:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-10 10:31:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 10:42:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FF40E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 10:42:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FF40E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 11:14:44  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x61FE70)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 11:14:44  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x61FE70)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 11:46:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD43149)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 11:46:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD43149)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 12:18:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1113ADC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 12:18:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1113ADC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 12:38:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14B51ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-10 12:38:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 12:38:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14B51ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 12:38:18  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14B5433)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 12:38:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14B543D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-10 12:38:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 12:38:28  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14B5433)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 12:50:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x16FEC63)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 12:50:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x16FEC63)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 13:22:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FB04D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 13:22:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FB04D2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 13:33:12  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FBE308)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3884     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1718    
    Security     Audit Success   2          2008-02-10 13:33:12  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FBE308)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 13:33:12  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3884    Source Network Address: 192.168.0.2    Source Port: 1718    
    Security     Audit Success   9          2008-02-10 13:33:12  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 13:44:02  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1fbe308)    
    Security     Audit Success   2          2008-02-10 13:44:03  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FBE308)     Logon Type: 10    
    Security     Audit Success   2          2008-02-10 13:54:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20CF4CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 13:54:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20CF4CD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 14:25:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27C6E1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 14:25:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27C6E1D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 14:57:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A9DBF2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 14:57:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A9DBF2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 15:29:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x31571D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 15:29:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x31571D3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 16:01:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3510D14)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 16:01:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3510D14)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 16:33:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3C53488)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 16:33:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3C53488)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 17:03:34  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 17:03:34  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 17:03:34  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 17:03:34  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 17:03:34  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 17:03:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18BCEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 17:03:44  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18E835)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 17:03:44  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18E835)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-10 17:03:44  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-10 17:03:44  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 17:05:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B5981)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 17:05:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B5981)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 17:37:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x362726)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 17:37:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x362726)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 17:52:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90430E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-10 17:52:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 18:08:12  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90430E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 18:09:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD30A91)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 18:09:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD30A91)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 18:41:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14CAC25)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 18:41:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14CAC25)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 18:53:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 18:53:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 18:53:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 18:53:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-10 18:53:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 18:53:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8040)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 18:53:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8040)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-10 18:53:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A7500)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-10 18:53:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-10 18:53:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 19:13:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x28AF2D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 19:13:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x28AF2D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 19:45:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x8EB9D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 19:45:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x8EB9D3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 20:17:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC3073A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 20:17:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC3073A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 20:49:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x112EC3F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 20:49:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x112EC3F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 21:10:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1545DEF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-10 21:10:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-10 21:10:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1545E46)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-10 21:10:30  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1545E46)     Logon Type: 3    
    Security     Audit Success   2          2008-02-10 21:10:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1545DEF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-12 08:33:05  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-12 08:33:05  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-12 08:33:05  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-12 08:33:05  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-12 08:33:05  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-12 08:33:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x160D5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-12 08:33:15  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1639B9)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-12 08:33:15  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1639B9)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-12 08:33:15  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 468    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-12 08:33:15  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:15:40  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-13 18:15:40  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-13 18:15:40  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-13 18:15:40  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-13 18:15:40  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-13 18:15:47  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17313A)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-13 18:15:47  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17313A)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-13 18:15:47  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1729B3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-13 18:15:47  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-13 18:15:47  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:16:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18B1E3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:16:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:16:22  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18B1E3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:19:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B6E10)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:19:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:19:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B70E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 18:19:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B70E4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:20:12  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BC3F1)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3648     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1183    
    Security     Audit Success   2          2008-02-13 18:20:12  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BC3F1)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-13 18:20:12  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3648    Source Network Address: 192.168.0.2    Source Port: 1183    
    Security     Audit Success   9          2008-02-13 18:20:12  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:25:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FC3CB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 18:25:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FC3CB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:33:00  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B6E10)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:33:00  SYSTEM                          Security                        683: Session disconnected from winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BC3F1)     Session Name: RDP-Tcp#1     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-02-13 18:38:10  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B0461)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1668     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1226    
    Security     Audit Success   2          2008-02-13 18:38:10  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B0461)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-13 18:38:10  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1668    Source Network Address: 192.168.0.2    Source Port: 1226    
    Security     Audit Success   9          2008-02-13 18:38:10  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:38:11  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B0461)     Logon Type: 10    
    Security     Audit Success   2          2008-02-13 18:38:11  SYSTEM                          Security                        682: Session reconnected to winstation:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BC3F1)     Session Name: RDP-Tcp#2     Client Name: BIER     Client Address: 192.168.0.2  
    Security     Audit Success   2          2008-02-13 18:38:58  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1bc3f1)    
    Security     Audit Success   2          2008-02-13 18:39:01  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BC3F1)     Logon Type: 10    
    Security     Audit Success   2          2008-02-13 18:41:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D6149)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:41:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:41:14  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D6149)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:41:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DB65B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:41:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:41:51  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DB65B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:41:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DD01E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:41:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:42:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DD01E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:43:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E9DCD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:43:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:43:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E9DCD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:43:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EF003)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-13 18:43:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-13 18:44:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EF003)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 18:57:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x54DD37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 18:57:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x54DD37)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 19:28:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD5A184)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 19:28:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD5A184)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 20:00:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE74052)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 20:00:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE74052)     Logon Type: 3    
    Security     Audit Success   2          2008-02-13 20:32:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x150DB9E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-13 20:32:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x150DB9E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 18:18:17  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 18:18:17  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-14 18:18:17  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 18:18:17  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-14 18:18:17  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 18:18:24  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14EDE8)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 18:18:24  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14EDE8)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-14 18:18:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14E7C9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 18:18:24  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-14 18:18:24  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-14 18:21:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1856D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 18:21:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1856D2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 18:23:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x199E87)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 18:23:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x199E95)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-14 18:23:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-14 18:23:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x199E87)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 18:23:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19BE3E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 18:23:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x19BE3E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 18:52:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3BDB8B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 18:52:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3BDB8B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 19:24:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC0C2AF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 19:24:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC0C2AF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 19:56:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCE3C79)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 19:56:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCE3C79)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 20:28:44  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x137C665)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 20:28:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x137C665)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 21:00:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B1E5C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 21:00:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B1E5C2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 21:31:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20004DC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-14 21:31:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20004DC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 21:46:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x199E95)     Logon Type: 3    
    Security     Audit Success   2          2008-02-14 22:28:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 22:28:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-14 22:28:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 22:28:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-14 22:28:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 22:28:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81D8C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 22:28:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x81D8C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-14 22:28:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7FE06)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-14 22:28:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-14 22:28:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 02:22:23  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 02:22:23  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 02:22:23  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 02:22:23  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 02:22:23  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 02:22:29  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9AA35)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 02:22:32  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9BB0C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 02:22:32  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9BB0C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-16 02:22:32  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-16 02:22:32  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 09:08:03  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 09:08:03  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 09:08:03  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 09:08:03  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 09:08:03  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 09:08:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7C667)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 09:08:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7C667)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-16 09:08:09  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7BB2D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 09:08:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-16 09:08:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:08:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x132FC1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 11:08:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x132FC1D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 11:10:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x13D2599)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 11:10:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13D273F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-16 11:10:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:10:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13D3F96)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 11:10:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:10:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x13D2599)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 11:10:35  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x140E179)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3436     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1202    
    Security     Audit Success   2          2008-02-16 11:10:35  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x140E179)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 11:10:35  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3436    Source Network Address: 192.168.0.2    Source Port: 1202    
    Security     Audit Success   9          2008-02-16 11:10:35  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:13:54  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x140e179)    
    Security     Audit Success   1          2008-02-16 11:13:59                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-02-16 11:15:06  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 11:15:06  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 11:15:06  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 11:15:06  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 11:15:06  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 11:15:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xEC2C4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 11:15:16  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEE97F)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 11:15:16  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEE97F)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-16 11:15:16  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-16 11:15:16  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:20:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A2EC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 11:20:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:30:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19C4B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 11:30:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:40:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E46FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 11:40:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 11:40:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E6176)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 11:40:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E6176)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 11:50:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x37450D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 11:50:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:00:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x745A83)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:00:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:10:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC09253)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:10:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:12:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD840D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 12:12:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD840D4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 12:20:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE37080)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:20:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:30:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x106D111)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:30:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:40:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B1622)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:40:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 12:44:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11B4373)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 12:44:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x11B4373)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 12:50:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11C8D70)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 12:50:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:00:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11CFE05)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:00:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:06:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12A06CB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 13:06:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12A06D5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-16 13:06:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:06:10  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12A06CB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 13:06:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12A56D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 13:06:18  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12A56D1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 13:06:18  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12A06D5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 13:10:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14A1E00)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:10:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:16:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14E3F82)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 13:16:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14E3F82)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 13:20:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16C7DE3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:20:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:30:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1856CD4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:30:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:40:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B7535D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:40:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 13:48:19  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1BD972C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 13:48:19  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1BD972C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 13:50:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BDA932)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 13:50:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:00:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BE112E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:00:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:10:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BF7DA4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:10:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:20:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EFA7F3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:20:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:20:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1EFA83D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 14:20:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1EFA83D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 14:30:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2250BE9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:30:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:40:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2276756)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:40:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:50:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25FCC4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 14:50:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 14:52:20  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25FE4E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 14:52:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25FE4E9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 15:00:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x260388E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:00:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:10:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2609AA2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:10:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:20:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x263B5F0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:20:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:24:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27CD083)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 15:24:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27CD083)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 15:30:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29225C5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:30:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:40:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C768B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:40:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:50:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C9D6EB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 15:50:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 15:56:21  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E15330)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 15:56:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E15330)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 16:01:46  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 16:01:46  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 16:01:46  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 16:01:46  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-16 16:01:46  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 16:01:52  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA60F0)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 16:01:52  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA60F0)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-16 16:01:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA5660)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-16 16:01:52  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-16 16:01:52  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 16:11:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x123C74)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 16:11:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 16:21:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x182BC4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 16:21:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 16:28:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B4E60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 16:28:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B4E60)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 16:31:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22615D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 16:31:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 16:41:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x51C3EA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 16:41:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 16:51:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x88AABA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 16:51:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:00:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x8F3736)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 17:00:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x8F3736)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 17:01:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x947CF2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:01:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:11:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC05CB4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:11:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:21:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC0C9AD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:21:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:31:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC12F68)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:31:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:32:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC13B0C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 17:32:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC13B0C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 17:41:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD271AB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:41:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 17:51:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF8410C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 17:51:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:01:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1352519)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:01:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:04:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14C624A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 18:04:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14C624A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 18:11:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1616481)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:11:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:21:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x176ACC1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:21:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:31:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A111D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:31:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:36:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19A4336)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 18:36:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x19A4336)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 18:41:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A7377)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:41:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 18:51:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19ADC98)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 18:51:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:01:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B75D60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:01:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:08:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1CB4BF2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 19:08:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1CB4BF2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 19:11:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5E111)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:11:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:21:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x203BA49)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:21:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:31:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212EEF7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:31:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:40:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x23B6431)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 19:40:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x23B6431)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 19:41:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B70C7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:41:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 19:51:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23BD9B8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 19:51:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:01:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23C3C79)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:01:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:11:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24ABEDB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:11:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:12:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x251638F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 20:12:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x251638F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 20:21:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x271BC52)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:21:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:31:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A51B71)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:31:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:41:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AD37C9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:41:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 20:44:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2B7CE68)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 20:44:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2B7CE68)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 20:51:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DCC6D6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 20:51:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:01:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DD2DE5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:01:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:11:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DE9458)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:11:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:16:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2DEC093)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 21:16:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2DEC093)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 21:21:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E6EBCD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:21:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:31:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30F11E0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:31:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:41:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3465BFA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:41:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 21:48:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3469A9D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-16 21:48:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3469A9D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 21:51:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3477C46)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 21:51:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 22:01:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x37F0767)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-16 22:01:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24ABEDB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF8410C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC12F68)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DE9458)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19ADC98)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1352519)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DCC6D6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23BD9B8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5E111)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AD37C9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A51B71)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3465BFA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3477C46)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x176ACC1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212EEF7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E6EBCD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30F11E0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x182BC4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x203BA49)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC05CB4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC0C9AD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x51C3EA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DD2DE5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1616481)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23C3C79)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23B70C7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B75D60)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x271BC52)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A111D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x947CF2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22615D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A7377)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x88AABA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x123C74)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD271AB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-16 22:06:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x37F0767)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 11:55:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB6D3F22)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 11:55:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 11:56:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB704493)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 11:56:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB704493)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 12:05:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB8B5E4B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:05:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:14:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBCEC8C8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:14:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:24:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBF7036C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:24:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:26:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBF79C72)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 12:26:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBF79C72)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 12:33:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC0A9D61)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:33:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:42:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC2F1C6F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:42:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:52:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC3082CF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 12:52:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 12:57:00  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC30AF90)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 12:57:00  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC30AF90)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 13:01:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC30DC18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:01:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:11:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC3B3979)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:11:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:20:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC626572)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:20:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:27:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC826638)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 13:27:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC826638)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 13:30:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC995986)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:30:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:39:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC9A0A7C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:39:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:49:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCD1005B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:49:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 13:57:29  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCD2B18C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 13:57:29  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCD2B18C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 13:58:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCD2BC18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 13:58:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:07:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCD32625)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:07:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:17:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCD48B98)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:17:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:26:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD036005)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:26:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:27:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD04B4FF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 14:27:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD04B4FF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 14:35:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD14218A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:35:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:45:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3CD8CF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:45:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:54:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD4E0C73)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 14:54:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 14:57:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD6435AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 14:57:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD6435AE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 15:03:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD74F4BD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:03:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:13:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD755977)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:13:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:22:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD75B1C5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:22:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:26:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD75DA5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 15:26:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD75DA5F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 15:31:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD7C8267)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:31:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:41:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA736E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:41:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:50:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDD5C620)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:50:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 15:56:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDDEA90C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 15:56:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDDEA90C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 15:59:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDDEC3AF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 15:59:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 16:08:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE0AD6DB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 16:08:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 16:18:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE176A84)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 16:18:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 16:26:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE17B1E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 16:26:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE17B1E6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 16:27:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE17BCE5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 16:27:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 16:36:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE180CB4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 16:36:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 16:58:45  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-17 16:58:45  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-17 16:58:45  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-17 16:58:45  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-17 16:58:45  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-17 16:58:52  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x133F90)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-17 16:58:52  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x133F90)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-17 16:58:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1338E0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-17 16:58:52  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-17 16:58:52  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:05:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19206F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:05:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:13:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DFB66)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:13:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:22:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x233C0A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:22:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:23:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x236788)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 17:23:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x236788)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 17:31:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D1C66)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:31:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:39:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5A0426)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:39:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:48:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x922D6E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:48:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 17:50:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x923F7F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 17:50:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x923F7F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 17:57:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x927746)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 17:57:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:05:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBED9AB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:05:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:14:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1011940)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:14:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:18:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x10953C1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 18:18:14  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x10953C1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 18:23:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1097BBC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:23:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:31:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1295EDA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:31:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:40:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x140FF71)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:40:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:45:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1412FD7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 18:45:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1412FD7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 18:49:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1414D3F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:49:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 18:57:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1422B7A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 18:57:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:07:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14C65AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:07:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:14:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17304BE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 19:14:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x17304BE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 19:16:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1731267)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:16:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:25:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AA4BB6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:25:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:35:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AA9A44)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:35:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:44:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2DB51)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:44:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 19:44:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E2DCDC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 19:44:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E2DCDC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 19:53:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E32749)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 19:53:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:02:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E3747C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:02:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:12:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E3C7E3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:12:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:14:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E461A1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 20:14:12  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E461A1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 20:21:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210CA57)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:21:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:30:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x229C15E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:30:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:40:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24C6EE4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:40:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:43:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x24C90D8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 20:43:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x24C90D8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 20:49:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2640068)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:49:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 20:58:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284014B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 20:58:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:08:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284E752)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:08:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:13:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2859408)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 21:13:48  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2859408)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 21:17:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x285B70B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:17:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:26:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2913638)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:26:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:35:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B61D42)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:35:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:42:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2DA8AD1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 21:42:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2DA8AD1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 21:43:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E8E52F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:43:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 21:52:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EEA474)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 21:52:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 22:00:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3169BB2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 22:00:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 22:09:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3262C58)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-17 22:09:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-17 22:09:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3262C88)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-17 22:09:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3262C88)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x140FF71)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1414D3F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B61D42)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DFB66)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3262C58)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1097BBC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210CA57)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AA4BB6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x927746)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1731267)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E3747C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x229C15E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3169BB2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24C6EE4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284014B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AA9A44)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D1C66)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1422B7A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1011940)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1295EDA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBED9AB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19206F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E32749)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2913638)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5A0426)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E8E52F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EEA474)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E3C7E3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x284E752)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2640068)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x922D6E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14C65AE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2DB51)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x233C0A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-17 22:15:45  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x285B70B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 18:31:03  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 18:31:03  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-18 18:31:03  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 18:31:03  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-18 18:31:03  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 18:31:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18C29E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 18:31:13  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18ED2F)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 18:31:13  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18ED2F)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-18 18:31:13  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-18 18:31:13  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 18:31:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A9BE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 18:31:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1A9BE7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 18:40:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FCEB7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 18:40:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 18:50:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x260324)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 18:50:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:00:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B17B5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:00:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:03:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x321699)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 19:03:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x321699)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 19:10:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D6C34)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:10:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:20:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E8E3A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:20:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:30:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x98480E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:30:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:35:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xAD09DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 19:35:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xAD09DE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 19:40:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCE48C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:40:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 19:50:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCFEFCC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 19:50:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 20:00:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD0A667)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 20:00:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 20:07:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD1FAFB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 20:07:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD1FAFB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 20:10:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD211D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 20:10:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 20:37:07  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 20:37:07  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-18 20:37:07  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 20:37:07  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-18 20:37:07  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 20:37:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1784D5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 20:37:16  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17C7A8)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-18 20:37:16  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17C7A8)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-18 20:37:16  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-18 20:37:16  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 20:39:57  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A8348)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 20:39:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1A8348)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 20:50:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F69B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 20:50:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:00:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28E043)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:00:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:10:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3AB20C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:10:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:11:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x42D431)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 21:11:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x42D431)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 21:20:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x72A886)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:20:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:30:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x98123A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:30:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:40:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBEE0FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:40:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 21:43:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCFFC25)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-18 21:43:59  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCFFC25)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 21:50:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD04392)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 21:50:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 22:00:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD09E99)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-18 22:00:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22F69B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBEE0FA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD09E99)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28E043)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD04392)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3AB20C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x72A886)     Logon Type: 3    
    Security     Audit Success   2          2008-02-18 22:01:27  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x98123A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-19 08:37:27  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-19 08:37:27  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-19 08:37:27  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-19 08:37:27  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-19 08:37:27  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-19 08:37:33  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12FC58)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-19 08:37:37  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x132864)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-19 08:37:37  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x132864)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-19 08:37:37  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-19 08:37:37  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-20 09:50:03  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-20 09:50:03  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-20 09:50:03  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-20 09:50:03  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-20 09:50:03  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-20 09:50:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A6B44)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-20 09:50:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A6B44)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-20 09:50:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A6522)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-20 09:50:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-20 09:50:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 00:29:53  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 00:29:53  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-22 00:29:53  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 00:29:53  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-22 00:29:53  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 00:29:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17E2EC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 00:29:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17E990)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 00:29:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17E990)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-22 00:29:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-22 00:29:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 08:25:47  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 08:25:47  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-22 08:25:47  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 08:25:47  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-22 08:25:47  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 08:25:54  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15BF5B)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 08:25:54  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15BF5B)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-22 08:25:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15B821)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-22 08:25:54  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-22 08:25:54  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 16:13:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x467F440)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 16:13:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 16:14:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x46B66CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 16:14:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x46B66CD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:17:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x477CE26)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-22 16:17:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 16:17:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x478025B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 16:17:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x478025B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:23:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A04E99)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 16:23:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 16:23:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4A04F55)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 16:23:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4A04F55)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:33:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A3CD9F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 16:33:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 16:40:32  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A3CD9F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:40:32  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4A04E99)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:40:32  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x467F440)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 16:40:32  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x477CE26)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:13:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61BA361)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 18:13:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 18:15:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6257CE4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:15:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6257CE4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:17:13  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x630319B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:17:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x63031C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-22 18:17:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 18:17:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x630319B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:23:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x654EA98)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 18:23:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 18:33:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6613D6A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 18:33:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 18:43:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x68DEC6E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 18:43:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 18:47:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6A9440C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:47:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6A9440C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:51:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6C6B0ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:51:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6C6B0ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:51:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6C6B670)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:51:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6C6B670)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:51:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6C6B6BE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 18:51:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6C6B6BE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 18:53:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6C6E486)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 18:53:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:03:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6D832F9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:03:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:13:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x700D60D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:13:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:19:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x701FC09)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 19:19:22  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x701FC09)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 19:23:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x702377D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:23:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:33:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7030301)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:33:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:43:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7281803)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:43:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 19:50:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7364A90)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 19:50:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7364A90)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 19:51:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x73B39C5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 19:51:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x73B39C5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 19:51:34  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x63031C2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 19:53:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x748B5B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 19:53:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:03:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x76E1D4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 20:03:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:13:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x79C54C9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 20:13:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:23:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7A7D6F7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-22 20:23:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7A7D6F7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:23:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A7D8C2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 20:23:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:33:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A89CDA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 20:33:35  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:43:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7AAB550)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-22 20:43:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x76E1D4D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7281803)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x79C54C9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6613D6A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6C6E486)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x702377D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x654EA98)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6D832F9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x700D60D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x61BA361)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x68DEC6E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7030301)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x748B5B7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A89CDA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7AAB550)     Logon Type: 3    
    Security     Audit Success   2          2008-02-22 20:46:29  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A7D8C2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 11:06:06  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-23 11:06:06  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-23 11:06:06  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-23 11:06:06  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-23 11:06:06  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-23 11:06:12  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x163CBA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-23 11:06:15  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x165EDF)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-23 11:06:15  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x165EDF)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-23 11:06:15  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-23 11:06:15  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 11:15:36  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CF64F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 11:15:36  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 11:16:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D99A7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 11:16:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D99A7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 11:25:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22AEAF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 11:25:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 11:35:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x295861)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 11:35:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 11:45:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57FFF7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 11:45:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 11:48:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x63A187)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 11:48:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x63A187)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 11:55:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x93D3D8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 11:55:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:05:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC08981)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:05:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:15:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCBDE4E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:15:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:20:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDCF2E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 12:20:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDCF2E6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 12:25:40  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1034BE7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:25:40  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:35:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x103D660)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:35:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:45:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1057DD9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:45:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 12:52:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x105B315)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 12:52:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x105B315)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 12:55:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x105CB93)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 12:55:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:05:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135E0E3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:05:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:15:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1623C87)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:15:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:24:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x16E601E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 13:24:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x16E601E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 13:25:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16E66DE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:25:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:35:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A63CB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:35:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:45:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A5E446)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:45:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:55:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A73224)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 13:55:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 13:56:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A73AC9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 13:56:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1A73AC9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 14:05:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A77406)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:05:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 14:15:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7817B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:15:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 14:25:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F50B96)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:25:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 14:28:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20F0CF4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 14:28:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20F0CF4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 14:35:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2100462)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:35:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 14:45:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22E9326)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:45:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 14:55:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x248875F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 14:55:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:00:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x248AA40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 15:00:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x248AA40)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 15:05:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x248CC1D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:05:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:15:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A186A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:15:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:25:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2768CD0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:25:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:32:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27DB573)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 15:32:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27DB573)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 15:35:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x289CF4C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:35:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:45:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B2B28F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:45:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 15:55:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C7364F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 15:55:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:02:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EA1FBE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-23 16:02:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:02:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2EA208D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 16:02:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2EA208D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 16:04:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2EA2F41)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 16:04:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2EA2F41)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 16:05:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EA3765)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:05:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:15:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EB8941)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:15:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:25:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EBD551)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:25:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:35:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30D3623)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:35:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:36:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3131805)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 16:36:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3131805)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 16:45:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x326EF72)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:45:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 16:55:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x35471E0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 16:55:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:06:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3629EFA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:06:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:08:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x373EB55)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 17:08:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x373EB55)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 17:16:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38C7996)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:16:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:26:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38CC4C3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:26:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:36:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38D9B6C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:36:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:40:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x38E3CD3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 17:40:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x38E3CD3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 17:46:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A20F5A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:46:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 17:56:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3C4C5C3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 17:56:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:06:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x40A3E57)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:06:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:12:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x43AA064)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 18:12:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x43AA064)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:16:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x447659C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:16:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:19:11  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4477999)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 18:19:21  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4477999)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:19:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4478082)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 18:19:58  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4478082)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:19:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x44780AA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 18:20:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x44780AA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:26:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x453CA5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:26:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:26:33  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EA1FBE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:28:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4654044)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-23 18:28:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:29:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4654044)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:36:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x47F601F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:36:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:44:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x48E12A6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 18:44:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x48E12A6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 18:46:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4941777)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:46:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 18:56:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B979A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 18:56:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:06:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4BA39F6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:06:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:16:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4BB3D12)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:16:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:16:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4BB536D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 19:16:53  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4BB536D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 19:26:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D8D9D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:26:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:36:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4F953FC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:36:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:46:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5268887)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:46:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 19:48:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x526B164)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 19:48:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x526B164)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 19:56:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5383D12)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 19:56:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:06:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x55F18B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:06:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:16:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5606976)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:16:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:20:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5616339)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 20:20:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5616339)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 20:26:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5626AF9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:26:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:36:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57D2FD4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:36:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:46:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59B9F0D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:46:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 20:52:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5C98C93)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 20:52:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5C98C93)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 20:56:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5CBB58E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 20:56:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:06:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5DB958F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:06:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:16:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x60589C0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:16:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:24:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6064472)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 21:24:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6064472)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 21:26:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6066373)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:26:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:36:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6071ADC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:36:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:46:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6250BF5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:46:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:56:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6434D1B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 21:56:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 21:56:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x645EFA8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 21:56:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x645EFA8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 22:06:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x67303A1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:06:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 22:16:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6821218)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:16:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 22:26:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6ABDC9C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:26:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 22:28:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6AC0744)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 22:28:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6AC0744)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 22:36:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6B1E515)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:36:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 22:46:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6B5DBEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:46:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 22:56:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6CA27AE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 22:56:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:00:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6E9AF11)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 23:00:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6E9AF11)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 23:06:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6F105B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:06:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:16:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x725F42F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:16:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:26:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x732AA7B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:26:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:32:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x760A998)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-23 23:32:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x760A998)     Logon Type: 3    
    Security     Audit Success   2          2008-02-23 23:36:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7635645)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:36:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:46:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7642FC6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:46:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-23 23:56:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x765EF4E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-23 23:56:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:04:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x769D482)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 00:04:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x769D482)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 00:06:30  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x76EC9E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:06:30  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:16:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A08F6F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:16:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:26:31  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7AE7B08)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:26:31  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:36:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DBA258)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:36:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:36:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7DBB308)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 00:36:56  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7DBB308)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 00:46:32  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DDAD20)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:46:32  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 00:56:33  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DFD194)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 00:56:33  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 01:06:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7EC862B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 01:06:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 01:08:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7FB8841)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 01:08:55  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7FB8841)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:16:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x813F762)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 01:16:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 01:26:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x84CE083)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 01:26:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 01:36:29  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x84F1E87)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 01:36:29  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 01:40:50  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x861D4F2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 01:40:50  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x861D4F2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x725F42F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5DB958F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x84CE083)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22E9326)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EBD551)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x60589C0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x289CF4C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DFD194)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6CA27AE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1623C87)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1057DD9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24A186A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2100462)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x47F601F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A77406)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x248CC1D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3A20F5A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5626AF9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6B1E515)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5268887)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6821218)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A08F6F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59B9F0D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x93D3D8)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135E0E3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x765EF4E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CF64F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCBDE4E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C7364F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F50B96)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57D2FD4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B979A2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6250BF5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3629EFA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x105CB93)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7642FC6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4941777)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x732AA7B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC08981)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6066373)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6ABDC9C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A73224)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EA3765)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2768CD0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5CBB58E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x57FFF7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22AEAF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4F953FC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x67303A1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19A63CB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7EC862B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4BB3D12)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x76EC9E9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B2B28F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4D8D9D2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x55F18B4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38CC4C3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x103D660)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3C4C5C3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x295861)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6071ADC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x40A3E57)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6434D1B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x248875F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5606976)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7635645)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6B5DBEA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16E66DE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x326EF72)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DBA258)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EB8941)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x35471E0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x447659C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4BA39F6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5383D12)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38D9B6C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7AE7B08)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1034BE7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6F105B0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A5E446)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30D3623)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x84F1E87)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x813F762)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x38C7996)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x453CA5F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7DDAD20)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 01:46:08  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D7817B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 13:29:23  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 13:29:23  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-24 13:29:23  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 13:29:23  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-24 13:29:23  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 13:29:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x186BF9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 13:29:35  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x187944)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 13:29:35  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x187944)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-24 13:29:35  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-24 13:29:35  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 13:29:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A04FC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-24 13:29:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 13:30:05  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A04FC)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 13:38:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FECF4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 13:38:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 13:42:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x222655)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 13:42:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x222655)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 13:48:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25D1FB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 13:48:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 13:58:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2DB8BD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 13:58:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:08:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5D47E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:08:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:14:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x76A9AD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 14:14:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x76A9AD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 14:18:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x966E1B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:18:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:29:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9D4E56)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:29:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:39:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEDDE2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:39:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:46:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCF95F6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 14:46:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCF95F6)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 14:49:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD02615)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:49:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 14:59:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD0BF37)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 14:59:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:09:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDAF9A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:09:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:18:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1020AEF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 15:18:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1020AEF)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 15:19:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1021018)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:19:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:29:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13A452B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:29:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:39:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13C6973)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:39:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:49:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x172AE6B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:49:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 15:50:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x172B793)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 15:50:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x172B793)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 15:59:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x172EFA6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 15:59:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:09:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1743877)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:09:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:19:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1784372)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:19:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:22:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x187E76B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 16:22:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x187E76B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 16:29:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A58579)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:29:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:39:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D96C4C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:39:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:49:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DDEE7D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:49:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 16:54:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1F09B56)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 16:54:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1F09B56)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 16:59:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x215114D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 16:59:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:09:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2155625)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 17:09:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:19:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x216A1AC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 17:19:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:26:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x216CD9F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 17:26:07  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x216CD9F)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 17:29:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x21890E1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 17:29:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:39:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246E88B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 17:39:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:52:21  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 17:52:21  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-24 17:52:21  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 17:52:21  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-24 17:52:21  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 17:52:28  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x139DE1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 17:52:32  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13AD36)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-24 17:52:32  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13AD36)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-24 17:52:32  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-24 17:52:32  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 17:58:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18E231)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 17:58:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x18E231)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 18:00:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A31B7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:00:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 18:10:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x222993)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:10:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 18:20:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28FB02)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:20:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 18:30:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x575C64)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 18:30:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x575C64)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 18:30:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59083C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:30:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 18:40:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E38A4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:40:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 18:50:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95154A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 18:50:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:00:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95B079)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:00:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:02:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x95BCEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 19:02:06  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x95BCEA)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 19:10:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95F155)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:10:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:20:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x973E19)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:20:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:30:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC744ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:30:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:34:07  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCE0AFB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 19:34:07  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCE0AFB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 19:40:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFB00F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:40:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 19:50:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFEA6F5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 19:50:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 20:00:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135C449)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-24 20:00:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 20:06:07  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x136F93C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 20:06:07  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x136F93C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E38A4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A31B7)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95F155)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95154A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135C449)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x973E19)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFB00F4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x222993)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFEA6F5)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x95B079)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC744ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59083C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:08:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28FB02)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:20:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x178CE56)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-24 20:20:36  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x178CE56)     Logon Type: 3    
    Security     Audit Success   2          2008-02-24 20:22:17  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1822881)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1040     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1059    
    Security     Audit Success   2          2008-02-24 20:22:17  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1822881)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-24 20:22:17  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1040    Source Network Address: 192.168.0.2    Source Port: 1059    
    Security     Audit Success   9          2008-02-24 20:22:17  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-24 20:23:02  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1822881)    
    Security     Audit Success   2          2008-02-24 20:24:11  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1822881)     Logon Type: 10    
    Security     Audit Success   2          2008-02-26 02:08:20  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 02:08:20  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-26 02:08:20  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 02:08:20  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-26 02:08:20  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 02:08:27  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x167A1E)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 02:08:27  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x167A1E)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-26 02:08:27  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1676F3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 02:08:27  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-26 02:08:27  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-26 22:13:48  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 22:13:48  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-26 22:13:48  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 22:13:48  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-26 22:13:48  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 22:13:55  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14C95C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 22:13:55  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14C95C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-26 22:13:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14C2F5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-26 22:13:55  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-26 22:13:55  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 18:00:48  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:00:48  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 18:00:48  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:00:48  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 18:00:48  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:00:55  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14EB5B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:00:58  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FE5C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:00:58  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14FE5C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-27 18:00:58  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 18:00:58  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 18:03:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17A770)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 18:03:02  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x17A770)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 18:56:28  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:56:28  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 18:56:28  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:56:28  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 18:56:28  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:56:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18F5AB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:56:38  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x190B60)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 18:56:38  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x190B60)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-27 18:56:38  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 18:56:38  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 18:59:03  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C3E2C)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3400     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2743    
    Security     Audit Success   2          2008-02-27 18:59:03  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C3E2C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 18:59:03  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3400    Source Network Address: 192.168.0.2    Source Port: 2743    
    Security     Audit Success   9          2008-02-27 18:59:03  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 19:04:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20BD70)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 948     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 19:04:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20BD70)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 19:04:09  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20BD70)     Logon Type: 4    
    Security     Audit Success   2          2008-02-27 19:04:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 948    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 19:04:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 19:04:51  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212109)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 948     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 19:04:51  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212109)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 19:04:51  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x212109)     Logon Type: 4    
    Security     Audit Success   2          2008-02-27 19:04:51  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 948    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 19:04:51  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 19:06:21  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22DDE0)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 948     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 19:06:21  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22DDE0)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 19:06:21  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22DDE0)     Logon Type: 4    
    Security     Audit Success   2          2008-02-27 19:06:21  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 948    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 19:06:21  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 19:06:40  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x239D80)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 948     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 19:06:40  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x239D80)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 19:06:40  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x239D80)     Logon Type: 4    
    Security     Audit Success   2          2008-02-27 19:06:40  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 948    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 19:06:40  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 19:06:52  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1c3e2c)    
    Security     Audit Success   2          2008-02-27 19:06:55  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C3E2C)     Logon Type: 10    
    Security     Audit Success   2          2008-02-27 19:07:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x243A20)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 19:07:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x243A20)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 19:39:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x7D5C64)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 19:39:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x7D5C64)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 20:11:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCFFF30)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 20:11:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCFFF30)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 20:34:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xEE4C49)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-27 20:34:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 20:34:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xEEC753)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 20:34:49  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xEEC753)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 20:43:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x104C009)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 20:43:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x104C009)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:07:32  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 21:07:32  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 21:07:32  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 21:07:32  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-27 21:07:32  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 21:07:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15E11B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 21:07:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15F1A4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-27 21:07:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15F1A4)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-27 21:07:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-27 21:07:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 21:15:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1C6394)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 21:15:24  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1C6394)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:16:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5183)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-27 21:16:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 21:26:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x233611)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-27 21:26:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 21:36:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E2204)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-27 21:36:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 21:36:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E6E88)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-27 21:36:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E6E88)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:36:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E6FC3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-27 21:36:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-27 21:37:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E6FC3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:38:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x233611)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:38:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E2204)     Logon Type: 3    
    Security     Audit Success   2          2008-02-27 21:38:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5183)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 00:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19AEA9D)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 868     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 00:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19AEA9D)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 00:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 868    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-28 00:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-02-28 00:00:04                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-02-28 18:50:00  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 18:50:00  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 18:50:00  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 18:50:00  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 18:50:00  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 18:50:06  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x11A64A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 18:50:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B5BD)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 18:50:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11B5BD)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-28 18:50:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-28 18:50:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 18:53:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14FD83)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 18:53:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14FD83)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 18:54:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16303C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-28 18:54:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 18:55:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16303C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 19:05:09  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C103B)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 4068     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1440    
    Security     Audit Success   2          2008-02-28 19:05:09  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C103B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 19:05:09  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 4068    Source Network Address: 192.168.0.2    Source Port: 1440    
    Security     Audit Success   9          2008-02-28 19:05:09  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:05:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D0742)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 860     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 19:05:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D0742)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 19:05:59  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D0742)     Logon Type: 4    
    Security     Audit Success   2          2008-02-28 19:05:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 860    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-28 19:05:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:06:18  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3262)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 860     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-28 19:06:18  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3262)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-28 19:06:18  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3262)     Logon Type: 4    
    Security     Audit Success   2          2008-02-28 19:06:18  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 860    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-28 19:06:18  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:06:27  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1c103b)    
    Security     Audit Success   2          2008-02-28 19:06:30  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C103B)     Logon Type: 10    
    Security     Audit Success   2          2008-02-28 19:10:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EF2C3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 19:10:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:20:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A6F5B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 19:20:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:20:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2AF72B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 19:20:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AF735)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-28 19:20:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:20:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2AF72B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 19:25:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x367078)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 19:25:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x367078)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 19:29:28  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2AF735)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 19:30:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x523942)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 19:30:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:40:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x850FB3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 19:40:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:50:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E374B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 19:50:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 19:57:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB6CD7D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 19:57:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB6CD7D)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 20:00:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB824A2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:00:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 20:10:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBA8C67)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:10:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 20:20:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBB6EF4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:20:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 20:29:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC1B49A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 20:29:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC1B49A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 20:30:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5F32E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:30:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 20:40:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE96F2A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:40:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 20:50:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11BD7E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 20:50:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 21:00:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1291849)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 21:00:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 21:01:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12B9286)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-28 21:01:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12B9286)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:10:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14E75D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-28 21:10:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBA8C67)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE96F2A)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBB6EF4)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB824A2)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A6F5B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EF2C3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14E75D1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8E374B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x523942)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x850FB3)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1291849)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5F32E)     Logon Type: 3    
    Security     Audit Success   2          2008-02-28 21:16:02  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11BD7E9)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 00:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E977CE)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 860     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E977CE)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 00:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 860    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 00:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-02-29 00:00:04                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-02-29 00:01:35  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:01:35  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 00:01:35  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:01:35  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 00:01:35  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:01:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x123B36)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:01:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x124641)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 00:01:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x124641)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-29 00:01:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 00:01:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 12:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6E4D7FA)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 880     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x6E4D7FA)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 12:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 880    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 12:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-02-29 12:00:01                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-02-29 12:01:33  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:01:33  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 12:01:33  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:01:33  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 12:01:33  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:01:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12BC3A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:01:43  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D22B)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 12:01:43  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12D22B)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-29 12:01:43  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 12:01:43  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:15:54  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 19:15:54  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 19:15:54  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 19:15:54  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 19:15:54  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 19:16:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x146D7E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 19:16:06  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x149F22)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 19:16:06  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x149F22)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-29 19:16:06  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 19:16:06  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:17:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16A8E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 19:17:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:27:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C55C1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 19:27:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:28:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D32E1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 19:28:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D32E1)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 19:36:47  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x206A3B)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3988     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1267    
    Security     Audit Success   2          2008-02-29 19:36:47  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x206A3B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 19:36:47  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3988    Source Network Address: 192.168.0.2    Source Port: 1267    
    Security     Audit Success   9          2008-02-29 19:36:47  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:36:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x208995)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-02-29 19:36:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:36:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x20910B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 19:37:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x20910B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 19:37:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x210260)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 19:37:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:38:07  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x206a3b)    
    Security     Audit Success   2          2008-02-29 19:38:39  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x206A3B)     Logon Type: 10    
    Security     Audit Success   2          2008-02-29 19:47:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x272290)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 19:47:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 19:57:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x34A663)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 19:57:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:00:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x446F34)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 20:00:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x446F34)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 20:03:27  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 20:03:27  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 20:03:27  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 20:03:27  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-02-29 20:03:27  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 20:03:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14153C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 20:03:38  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1436B8)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-02-29 20:03:38  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1436B8)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-02-29 20:03:38  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-02-29 20:03:38  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:07:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x183A66)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:07:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:17:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E58ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:17:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:27:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2308F0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:27:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:32:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25B7CD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 20:32:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25B7CD)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 20:37:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28C690)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:37:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:47:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4840CE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:47:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 20:57:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x91DEBB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 20:57:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 21:04:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x95F22B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 21:04:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x95F22B)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:07:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x965EE3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 21:07:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 21:17:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEC520)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 21:17:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 21:27:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCFFD0C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 21:27:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 21:36:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD14180)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-02-29 21:36:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD14180)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD17E56)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-02-29 21:37:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEC520)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4840CE)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E58ED)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2308F0)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCFFD0C)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28C690)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x91DEBB)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD17E56)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x183A66)     Logon Type: 3    
    Security     Audit Success   2          2008-02-29 21:37:36  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x965EE3)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 09:02:52  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 09:02:52  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-01 09:02:52  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 09:02:52  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-01 09:02:52  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 09:03:01  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x152404)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 09:03:01  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x152404)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-01 09:03:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x151C7E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 09:03:01  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-01 09:03:01  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 09:07:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19215A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 09:07:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x19215A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 09:10:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B1584)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 09:10:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 09:20:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FD68C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 09:20:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 09:30:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x24201B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 09:30:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 09:39:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27F7D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 09:39:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27F7D3)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 09:40:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x281C06)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 09:40:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 09:50:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4BB185)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 09:50:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:00:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x84E661)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:00:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:10:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9EE098)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:10:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:11:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F34B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 10:11:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F34B1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 10:20:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD142C1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:20:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:30:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD2B9C7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:30:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:40:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1065D28)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:40:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 10:43:37  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x106AE46)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 10:43:37  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x106AE46)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 10:50:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x117621C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 10:50:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:00:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13C0764)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:00:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:10:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1694664)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:10:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:15:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1762AC1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 11:15:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1762AC1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 11:20:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x176B4FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:20:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:30:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A8D195)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:30:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:40:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B4769C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:40:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 11:47:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E6DFF7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 11:47:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E6DFF7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 11:50:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EE7D49)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 11:50:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x231742B)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 880     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x231742B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-01 12:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 880    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-01 12:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-03-01 12:00:01                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-01 12:01:35  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:01:35  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-01 12:01:35  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:01:35  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-01 12:01:35  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:01:41  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x139616)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:01:41  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x139616)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-01 12:01:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1390F1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-01 12:01:41  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-01 12:01:41  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:11:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B035D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 12:11:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:19:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1F1B4E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 12:19:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1F1B4E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 12:21:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FC6D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 12:21:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:31:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2475EF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 12:31:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:41:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C5E53)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 12:41:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:51:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E980A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 12:51:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 12:51:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6044FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 12:51:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6044FA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 13:01:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x94687A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:01:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:11:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA83A48)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:11:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:21:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEE759)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:21:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:23:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCF4453)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 13:23:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCF4453)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 13:23:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCF448D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-01 13:23:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:23:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCF4633)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 13:23:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCF4633)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 13:23:58  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCF448D)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 13:24:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3B87B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-01 13:24:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:24:55  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD3B87B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 13:31:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1080BCC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:31:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:41:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1090EFF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:41:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:51:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x141015C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 13:51:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 13:55:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1420BC4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 13:55:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1420BC4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 14:01:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1429BA5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:01:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:11:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x143E8C8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:11:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:21:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1524DCC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:21:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:27:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1758203)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 14:27:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1758203)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 14:31:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x178EF08)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:31:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:41:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ADCB4B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:41:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:51:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BF8213)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-01 14:51:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-01 14:59:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E6BB51)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-01 14:59:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E6BB51)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1524DCC)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA83A48)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1080BCC)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B035D)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2475EF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x143E8C8)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BF8213)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ADCB4B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C5E53)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FC6D2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEE759)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x141015C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1429BA5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x94687A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1090EFF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x178EF08)     Logon Type: 3    
    Security     Audit Success   2          2008-03-01 15:02:13  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E980A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 10:02:31  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 524     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 10:02:31  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-09 10:02:31  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 524     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 10:02:31  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-09 10:02:31  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 10:02:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19E9E8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 10:02:42  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19F4F7)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 524     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 10:02:42  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19F4F7)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-09 10:02:42  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 524    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-09 10:02:42  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:09:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20CF0B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:09:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:12:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x222557)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 10:12:47  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x222557)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 10:19:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2605F0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:19:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:29:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2B2E74)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:29:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:39:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3071E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:39:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:44:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x37EF6F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 10:44:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x37EF6F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 10:49:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4E9539)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:49:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 10:59:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x90BB8C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 10:59:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 11:10:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xA19AD1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 11:10:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 11:16:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC7CCEB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 11:16:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC7CCEB)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 11:20:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA61EF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 11:20:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 11:30:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDC2865)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 11:30:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 11:40:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDDB09C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 11:40:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 11:48:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDF0427)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 11:48:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDF0427)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 11:50:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE3281B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 11:50:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:14:17  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 12:14:17  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-09 12:14:17  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 12:14:17  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-09 12:14:17  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 12:14:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12097A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 12:14:27  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x121D23)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-09 12:14:27  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x121D23)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-09 12:14:27  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-09 12:14:27  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:20:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18B756)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 12:20:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x18B756)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 12:22:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19488B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 12:22:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:32:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F0360)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 12:32:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:42:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x257744)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 12:42:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:52:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BA51C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 12:52:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 12:52:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2C0FDC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 12:52:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2C0FDC)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 13:02:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x44AB0F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:02:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:12:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x882557)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:12:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:22:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9C0606)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:22:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:24:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F3D27)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 13:24:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F3D27)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 13:32:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD4E310)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:32:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:42:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD6A8FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:42:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:52:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD840F7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 13:52:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 13:56:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD9259F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 13:56:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD9259F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 14:02:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDA86CC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:02:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 14:12:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x10B3DDC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:12:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 14:22:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14431C3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:22:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 14:28:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1451010)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 14:28:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1451010)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 14:32:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14BFA3B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:32:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 14:42:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17E56E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:42:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 14:52:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17F7C88)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 14:52:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:00:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1805533)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 15:00:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1805533)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 15:02:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18076E1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:02:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:12:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1946E46)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:12:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:22:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1BCC154)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:22:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:32:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EC93EF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:32:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:32:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1EC9BBE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 15:32:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1EC9BBE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 15:37:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1ED91D7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 15:37:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ED91F4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-09 15:37:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:38:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1ED91D7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 15:42:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F5F896)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:42:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:52:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x222EC3C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 15:52:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 15:58:04  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ED91F4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 16:02:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x25970CB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:02:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 16:04:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x26690C5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 16:04:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x26690C5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 16:12:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28D5BE0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:12:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 16:22:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A35E02)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:22:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 16:32:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2C80AD8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:32:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 16:36:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2CC8E35)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 16:36:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2CC8E35)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 16:42:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2CEBD20)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:42:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 16:52:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D1CACC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 16:52:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 17:02:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2FD4B7C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 17:02:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 17:08:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x307C8B1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 17:08:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x307C8B1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 17:12:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x322099B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 17:12:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 17:22:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x344A18A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-09 17:22:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-09 17:40:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x380C15D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 17:40:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x380C15D)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 18:12:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3BB7130)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 18:12:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3BB7130)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 18:44:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3F882FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 18:44:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3F882FA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 19:16:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4648815)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 19:16:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4648815)     Logon Type: 3    
    Security     Audit Success   2          2008-03-09 19:48:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4A04E92)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-09 19:48:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4A04E92)     Logon Type: 3    
    Security     Audit Success   2          2008-03-12 00:11:58  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 00:11:58  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-12 00:11:58  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 00:11:58  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-12 00:11:58  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 00:12:05  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x193275)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 00:12:05  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x193275)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-12 00:12:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x192CDE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 00:12:05  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 468    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-12 00:12:05  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-12 12:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x75E0BC9)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 880     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x75E0BC9)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-12 12:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 880    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-12 12:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-03-12 12:00:01                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-12 12:01:32  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:01:32  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-12 12:01:32  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:01:32  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-12 12:01:32  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:01:39  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15B5B9)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:01:39  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15B5B9)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-12 12:01:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15ACE2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-12 12:01:39  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-12 12:01:39  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-12 18:02:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3A09536)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-12 18:02:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3A09536)     Logon Type: 3    
    Security     Audit Success   2          2008-03-12 18:34:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x40CCACF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-12 18:34:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x40CCACF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-12 18:40:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x440A0CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-12 18:40:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-12 18:40:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x440A170)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-12 18:40:44  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x440A170)     Logon Type: 3    
    Security     Audit Success   2          2008-03-12 18:58:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4615AD6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-12 18:59:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4615AD6)     Logon Type: 3    
    Security     Audit Success   2          2008-03-12 19:04:38  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x440A0CA)     Logon Type: 3    
    Security     Audit Success   9          2008-03-13 00:00:01  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 00:00:02  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7A350FE)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 876     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:00:02  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name:      Domain:       Logon ID:  (0x0,0x7A350FE)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 00:00:02  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 876    Source Network Address: -    Source Port: -    
    Security     Audit Success   1          2008-03-13 00:00:10                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-13 00:01:47  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:01:47  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 00:01:47  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:01:47  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 00:01:47  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:01:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x15A48B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:01:57  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C597)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 00:01:57  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C597)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-13 00:01:57  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-13 00:01:57  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:23:18  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 18:23:18  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 18:23:18  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 18:23:18  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 18:23:18  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 18:23:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1762D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 18:23:29  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x177797)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 18:23:29  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x177797)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-13 18:23:29  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 468    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-13 18:23:29  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:24:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x194EB1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 18:24:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:25:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1A35F7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 18:25:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1A35F7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 18:33:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1EC587)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 18:33:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1EC591)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-13 18:33:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:33:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1EC587)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 18:34:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1F331C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 18:34:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:44:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x249033)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 18:44:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:54:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28E736)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 18:54:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 18:57:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A7855)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 18:57:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A7855)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 19:04:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EB8D0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:04:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 19:14:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3F4C94)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:14:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 19:24:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x80843B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:24:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 19:29:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9A33EA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 19:29:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9A33EA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 19:29:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9A3935)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 19:29:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9A3935)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 19:34:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9B0C79)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:34:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 19:44:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD41749)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:44:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 19:54:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD6CACF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 19:54:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:01:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD7846A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 20:01:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD7846A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 20:04:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD817F8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 20:04:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:14:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD95CDA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 20:14:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:24:40  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 20:24:40  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 20:24:40  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 20:24:40  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-13 20:24:40  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 20:24:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x192844)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 20:24:51  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x193B5B)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 532     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-13 20:24:51  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x193B5B)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-13 20:24:51  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 532    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-13 20:24:51  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:33:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x203915)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 20:33:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x203915)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 20:35:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2164BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 20:35:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:45:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26176D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 20:45:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 20:55:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BD9D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 20:55:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:03:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2FB03E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 21:03:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2FB05E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-13 21:03:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:03:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2FB03E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:03:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2FB4E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 21:03:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2FB4E6)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:05:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30BAD9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 21:05:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:05:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x30F488)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 21:05:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x30F488)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:15:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x479734)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 21:15:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:25:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8B0244)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 21:25:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:33:10  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9D5DFE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 21:33:20  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9D5DFE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:35:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DC097)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 21:35:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:37:46  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xA065D0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-13 21:37:46  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xA065D0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:45:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD705FF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-13 21:45:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-13 21:47:03  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2FB05E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2BD9D2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30BAD9)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD705FF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x479734)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26176D)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2164BA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8B0244)     Logon Type: 3    
    Security     Audit Success   2          2008-03-13 21:53:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9DC097)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 00:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23DE38C)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 948     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23DE38C)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 00:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 948    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-14 00:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-03-14 00:00:03                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-14 00:01:35  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:01:35  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 00:01:35  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:01:35  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 00:01:35  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:01:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x156289)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:01:45  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x156C14)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 00:01:45  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x156C14)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-14 00:01:45  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-14 00:01:45  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 17:45:52  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 17:45:52  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 17:45:52  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 17:45:52  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 17:45:52  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 17:45:59  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x153282)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 17:46:02  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1546A1)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 17:46:02  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1546A1)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-14 17:46:02  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-14 17:46:02  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 17:48:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x187A46)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 17:48:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x187A46)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 18:20:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2E40E2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 18:20:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2E40E2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 18:21:11  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EB5D9)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 1528     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1376    
    Security     Audit Success   2          2008-03-14 18:21:11  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2EB5D9)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 18:21:11  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 1528    Source Network Address: 192.168.0.2    Source Port: 1376    
    Security     Audit Success   9          2008-03-14 18:21:11  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:24:00  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2eb5d9)    
    Security     Audit Success   1          2008-03-14 18:24:07                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-14 18:25:23  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 18:25:23  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 18:25:23  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 18:25:23  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 18:25:23  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 18:25:30  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1361F1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 18:25:34  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x136F4C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-14 18:25:34  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x136F4C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-14 18:25:34  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-14 18:25:34  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:26:33  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C1C7)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3108     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1453    
    Security     Audit Success   2          2008-03-14 18:26:33  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C1C7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-14 18:26:33  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3108    Source Network Address: 192.168.0.2    Source Port: 1453    
    Security     Audit Success   9          2008-03-14 18:26:33  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:33:56  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15c1c7)    
    Security     Audit Success   2          2008-03-14 18:33:59  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x15C1C7)     Logon Type: 10    
    Security     Audit Success   2          2008-03-14 18:34:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C7103)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-14 18:34:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:34:04  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1C7287)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 18:34:13  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1C7287)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 18:35:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CE0C0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 18:35:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:38:43  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C7103)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 18:45:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x230789)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 18:45:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 18:52:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x27330B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 18:52:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x27330B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 18:55:11  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28C1D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 18:55:11  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:05:12  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F8530)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:05:12  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:15:13  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8FC40F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:15:13  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:24:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE0678A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 19:24:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE0678A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 19:25:14  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE07B60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:25:14  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:35:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x104BE32)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:35:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:45:15  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x143949F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:45:15  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:55:16  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14565BE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 19:55:16  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 19:56:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x14593E7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 19:56:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x14593E7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 20:05:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147609B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:05:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 20:15:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1855C96)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:15:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 20:25:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B698FA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:25:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 20:28:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E4DB41)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 20:28:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E4DB41)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 20:35:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FF70A5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:35:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 20:45:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2302494)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:45:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 20:55:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2617190)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 20:55:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:00:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x262218B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 21:00:26  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x262218B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 21:05:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26314CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:05:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:15:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2647222)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:15:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:25:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29CEA13)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:25:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:32:25  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2C9CFB5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 21:32:25  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2C9CFB5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 21:35:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E15963)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:35:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:45:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x334C2BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:45:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:51:42  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x369E180)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 21:51:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x369E18A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-14 21:51:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 21:51:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x369E180)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 21:55:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x370F822)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-14 21:55:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-14 22:04:23  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3ABF159)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-14 22:04:23  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3ABF159)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:06  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x369E18A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1CE0C0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2302494)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2E15963)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x334C2BA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x230789)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE07B60)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28C1D4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x104BE32)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26314CA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x14565BE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F8530)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8FC40F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29CEA13)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147609B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2647222)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x143949F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FF70A5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2617190)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1855C96)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x370F822)     Logon Type: 3    
    Security     Audit Success   2          2008-03-14 22:16:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B698FA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 00:00:00  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x644224F)     Logon Type: 4     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 856     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:00:00  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x644224F)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 00:00:00  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 856    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-15 00:00:00  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   1          2008-03-15 00:00:03                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-15 00:01:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:01:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 00:01:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:01:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 00:01:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:01:43  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1AD267)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:01:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ADA6A)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 536     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 00:01:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1ADA6A)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-15 00:01:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 536    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-15 00:01:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:45:45  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 12:45:45  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 12:45:45  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 12:45:45  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 12:45:45  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 12:45:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x122A4D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 12:45:56  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1232F0)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-15 12:45:56  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1232F0)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-15 12:45:56  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-15 12:45:56  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:45:59  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135BC7)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 412     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-03-15 12:45:59  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x135BC7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 12:45:59  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 412    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-03-15 12:45:59  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:46:31  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x141258)     Logon Type: 2     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 412     Transited Services: -     Source Network Address: 127.0.0.1     Source Port: 0    
    Security     Audit Success   2          2008-03-15 12:46:31  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x141258)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-15 12:46:31  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 412    Source Network Address: 127.0.0.1    Source Port: 0    
    Security     Audit Success   9          2008-03-15 12:46:31  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:53:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18D4DC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 12:53:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:54:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18F76F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-15 12:54:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 12:54:07  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18FA77)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 12:54:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x18FA77)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 12:57:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B2C99)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 12:57:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B2C99)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 13:03:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DEEAF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:03:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 13:13:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B694)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:13:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 13:23:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26EA6E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:23:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 13:29:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x470E88)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 13:29:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x470E88)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 13:33:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E26F7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:33:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 13:43:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8439FC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:43:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 13:53:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xABA35E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 13:53:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:01:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB94038)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 14:01:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB94038)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 14:03:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB9AF05)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:03:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:13:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBC2D3C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:13:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:19:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBD280F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 14:20:04  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBD280F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 14:23:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCA601E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:23:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:33:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xF1BAA2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 14:33:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xF1BAA2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 14:33:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF240A0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:33:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:43:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1125892)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:43:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 14:48:24  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1260C45)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 14:48:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1260C45)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 14:53:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x127B8B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 14:53:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:03:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12B6F77)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:03:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:05:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x12C1E19)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 15:05:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x12C1E19)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 15:13:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12E5BEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:13:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:23:54  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1633417)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:23:54  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:33:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16C1EBE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:33:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:37:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1879658)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 15:37:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1879658)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 15:43:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x198478F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:43:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 15:53:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19ACA3E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 15:53:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:03:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19CAF24)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:03:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:09:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19DACBF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 16:09:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x19DACBF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 16:13:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B63CD1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:13:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:23:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D931D4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:23:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:33:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FFE2E6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:33:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:41:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x211C398)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 16:41:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x211C398)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 16:44:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2295F1A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:44:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 16:54:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2362BBD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 16:54:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:04:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23780F1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:04:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:13:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2386ED8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 17:13:34  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2386ED8)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 17:14:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23877B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:14:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:24:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26AEEE4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:24:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:34:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29D9848)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:34:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:44:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A3198F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:44:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 17:45:34  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A8F265)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 17:45:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A8F265)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 17:54:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D70F93)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 17:54:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:04:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F4A449)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:04:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:14:07  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30DB086)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:14:07  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:17:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x311324F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 18:17:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x311324F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 18:24:08  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x340B0BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:24:08  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:34:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3435894)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:34:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:44:09  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3448527)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:44:09  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 18:49:35  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x345565C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 18:49:35  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x345565C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 18:54:10  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x346A64A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 18:54:10  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x30DB086)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2F4A449)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2295F1A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCA601E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x22B694)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1FFE2E6)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x346A64A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1633417)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2A3198F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB9AF05)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x29D9848)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19CAF24)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xABA35E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B63CD1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23780F1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D931D4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5E26F7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x127B8B4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2D70F93)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x23877B4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1125892)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x19ACA3E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x340B0BA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF240A0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26EA6E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12E5BEA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12B6F77)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8439FC)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1DEEAF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2362BBD)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3435894)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x3448527)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x16C1EBE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18D4DC)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x198478F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xBC2D3C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x26AEEE4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:02:35  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x18F76F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:45:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4192F91)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 19:45:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 19:47:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x421D59E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 19:47:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x421D59E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 19:55:56  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x44D7CD0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 19:55:56  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:05:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x45DE485)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:05:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:15:57  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x497D3A7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:15:57  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:19:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4B4C6D8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 20:19:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4B4C6D8)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 20:25:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B6144B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:25:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:35:58  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4E55687)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:35:58  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:45:59  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EB1DE6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:45:59  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 20:51:41  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4EBD4ED)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 20:51:41  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4EBD4ED)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 20:56:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4ED69C1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 20:56:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:06:00  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EEAC45)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:06:00  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:16:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x51C0BA5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:16:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:23:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x53B359B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 21:23:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x53B359B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 21:26:01  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x54E6632)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:26:01  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:36:02  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x553030F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:36:02  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:46:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x585303C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:46:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 21:55:40  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5870738)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-15 21:55:40  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5870738)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 21:56:03  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587118C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 21:56:03  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 22:06:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x58835D2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 22:06:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 22:16:04  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59958D8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 22:16:04  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 22:26:05  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5C1DE2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-15 22:26:05  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x497D3A7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4ED69C1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x54E6632)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4B6144B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x587118C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x45DE485)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x44D7CD0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x51C0BA5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x585303C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x553030F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4192F91)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4E55687)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EB1DE6)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x59958D8)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x58835D2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EEAC45)     Logon Type: 3    
    Security     Audit Success   2          2008-03-15 22:26:53  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5C1DE2E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 09:54:17  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5A9BEB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 09:54:17  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 09:55:14  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC5B376F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 09:55:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC5B376F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 10:04:18  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5DFF4E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:04:18  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:10:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC5FC04C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 10:10:06  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5FC057)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-16 10:10:06  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:10:16  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC5FC04C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 10:14:19  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC618AD4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:14:19  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:24:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC92DAA6)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:24:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:27:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xC93970C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 10:27:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xC93970C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 10:34:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCADCC60)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:34:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:44:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEA7DE8)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:44:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:54:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xCEE6827)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 10:54:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 10:59:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD080D07)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 10:59:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD080D07)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 11:04:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD227026)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:04:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 11:14:24  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD250FD1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:14:24  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 11:24:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD273502)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:24:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 11:31:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD292DAE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 11:31:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD292DAE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 11:34:25  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD31531F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:34:25  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 11:44:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD579D79)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:44:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 11:54:26  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD8B57FD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 11:54:26  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:03:15  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD8EF55E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 12:03:15  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD8EF55E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 12:04:27  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD8FC041)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 12:04:27  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:14:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDC0BFBA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 12:14:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:24:28  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDCAD49F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 12:24:28  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:25:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDD15E2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 12:26:01  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDD15E2E)     Logon Type: 3    
    Security     Audit Success   9          2008-03-16 12:34:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:34:35  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDD498BC)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 12:35:16  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDD4AA5C)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 12:35:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDD4AA5C)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 12:44:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDD74FF2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 12:44:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 12:54:37  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xDDA6AC3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 12:54:37  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:04:38  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE0CCC5A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 13:04:38  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:07:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE0D19CA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 13:07:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE0D19CA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 13:14:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE1CFBD4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 13:14:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:17:01  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE2EE082)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 13:17:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE2EE082)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 13:17:11  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xC5FC057)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 13:24:39  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE40DC4F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 13:24:39  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:36:27  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 13:36:27  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 13:36:27  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 13:36:27  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 13:36:27  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 13:36:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x81AA0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 13:36:39  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x82838)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 13:36:39  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x82838)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-16 13:36:39  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-16 13:36:39  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:39:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB0FC9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 13:39:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB0FC9)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 13:42:01  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD73EB)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3512     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2658    
    Security     Audit Success   2          2008-03-16 13:42:01  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD73EB)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 13:42:01  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3512    Source Network Address: 192.168.0.2    Source Port: 2658    
    Security     Audit Success   9          2008-03-16 13:42:01  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:45:41  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFDEB1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 13:45:41  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 13:52:07  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xd73eb)    
    Security     Audit Success   2          2008-03-16 13:52:10  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xD73EB)     Logon Type: 10    
    Security     Audit Success   2          2008-03-16 13:55:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1542B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 13:55:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:05:42  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A42B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:05:42  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:06:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0AC5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-16 14:06:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:06:48  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1B0D2A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 14:06:57  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1B0D2A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:07:14  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C528F)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 360     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2771    
    Security     Audit Success   2          2008-03-16 14:07:14  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C528F)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 14:07:14  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 360    Source Network Address: 192.168.0.2    Source Port: 2771    
    Security     Audit Success   9          2008-03-16 14:07:14  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:10:21  IUSR_WEBERSERVER                Security                        540: Successful Network Logon:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28B53D)     Logon Type: 8     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: NETWORK SERVICE     Caller Domain: NT AUTHORITY     Caller Logon ID: (0x0,0x3E4)     Caller Process ID: 4016     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 14:10:21  NETWORK SERVICE                 Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon GUID: -    User whose credentials were used:     Target User Name: IUSR_WEBERSERVER     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 4016    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-16 14:10:21  IUSR_WEBERSERVER                Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: IUSR_WEBERSERVER    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:11:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2F2206)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 14:11:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2F2206)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:12:19  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1c528f)    
    Security     Audit Success   2          2008-03-16 14:15:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EE72E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:15:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:17:37  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1C528F)     Logon Type: 10    
    Security     Audit Success   2          2008-03-16 14:21:14  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7040CB)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 14:21:14  Administrator                   Security                        540: Successful Network Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7040CB)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2815    
    Security     Audit Success   9          2008-03-16 14:21:14  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:21:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1A42B0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:21:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1542B0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:21:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xFDEB1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:21:16  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x4EE72E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:25:43  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x87753D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:25:43  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:25:51  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8859F4)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 940     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 2823    
    Security     Audit Success   2          2008-03-16 14:25:51  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8859F4)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 14:25:51  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 940    Source Network Address: 192.168.0.2    Source Port: 2823    
    Security     Audit Success   9          2008-03-16 14:25:51  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:27:42  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8859f4)    
    Security     Audit Success   2          2008-03-16 14:28:19  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x8859F4)     Logon Type: 10    
    Security     Audit Success   2          2008-03-16 14:28:48  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B0AC5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:35:44  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xB29504)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:35:44  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:41:24  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x7040CB)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:41:25  IUSR_WEBERSERVER                Security                        538: User Logoff:     User Name: IUSR_WEBERSERVER     Domain:  WEBERSERVER     Logon ID:  (0x0,0x28B53D)     Logon Type: 8    
    Security     Audit Success   2          2008-03-16 14:43:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xE498B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 14:43:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xE498B2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 14:45:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE4BA71)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:45:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:52:44  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE5EBE7)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 896     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3095    
    Security     Audit Success   2          2008-03-16 14:52:44  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xE5EBE7)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 14:52:44  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 896    Source Network Address: 192.168.0.2    Source Port: 3095    
    Security     Audit Success   9          2008-03-16 14:52:44  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 14:55:45  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0xF2E708)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 14:55:45  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:05:46  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x11F5405)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:05:46  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:15:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1223515)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 15:15:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1223515)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 15:15:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1223FB3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:15:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:25:47  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1238E79)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:25:47  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:35:48  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x12FCA25)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:35:48  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:39:10  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0xe5ebe7)    
    Security     Audit Success   1          2008-03-16 15:39:19                                  SECURITY                        513: Windows is shutting down.  All logon sessions will be terminated by this shutdown.  
    Security     Audit Success   2          2008-03-16 15:43:39  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 15:43:39  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 15:43:39  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 15:43:39  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 15:43:39  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 15:43:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x121769)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 15:43:46  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x121A37)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 460     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-16 15:43:46  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x121A37)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-16 15:43:46  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 460    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-16 15:43:46  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:45:08  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147F6B)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3096     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 3717    
    Security     Audit Success   2          2008-03-16 15:45:08  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147F6B)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-16 15:45:08  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3096    Source Network Address: 192.168.0.2    Source Port: 3717    
    Security     Audit Success   9          2008-03-16 15:45:08  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:45:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x152B5F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:45:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:47:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x164D25)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 15:47:18  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x164D25)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 15:48:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x175813)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 15:48:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17581E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 15:48:51  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x17581E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 15:48:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x175860)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-16 15:48:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   9          2008-03-16 15:48:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 15:49:01  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x175813)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 15:50:58  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x175860)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 15:52:23  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147f6b)    
    Security     Audit Success   2          2008-03-16 15:52:27  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x147F6B)     Logon Type: 10    
    Security     Audit Success   2          2008-03-16 15:55:49  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B8BFA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 15:55:49  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:05:50  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20140A)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 16:05:50  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:15:51  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246030)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 16:15:51  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:19:18  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A09B0)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 16:19:18  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A09B0)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:25:52  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x538339)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 16:25:52  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:35:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x62F7BD)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 16:35:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:45:53  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x955238)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-16 16:45:53  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-16 16:51:18  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xB25204)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-16 16:51:18  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xB25204)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x955238)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1B8BFA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x20140A)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x62F7BD)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x246030)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x152B5F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-16 16:57:50  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x538339)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 18:30:40  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-18 18:30:40  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-18 18:30:40  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-18 18:30:40  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-18 18:30:40  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-18 18:30:49  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AD3DD)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-18 18:30:49  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1AD3DD)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-18 18:30:49  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1ABDC3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-18 18:30:49  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-18 18:30:49  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-18 18:32:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1E07EE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 18:32:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1E07EE)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 18:33:17  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2FCF)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3276     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1133    
    Security     Audit Success   2          2008-03-18 18:33:17  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2FCF)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-18 18:33:17  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3276    Source Network Address: 192.168.0.2    Source Port: 1133    
    Security     Audit Success   9          2008-03-18 18:33:17  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-18 19:04:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x25ABEA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 19:04:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x25ABEA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 19:36:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2CB082)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 19:36:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2CB082)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 20:08:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x934E40)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 20:08:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x934E40)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 20:11:15  Administrator                   Security                        551: User initiated logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1e2fcf)    
    Security     Audit Success   2          2008-03-18 20:14:24  Administrator                   Security                        538: User Logoff:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E2FCF)     Logon Type: 10    
    Security     Audit Success   2          2008-03-18 20:40:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x113E2E4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 20:40:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x113E2E4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-18 21:12:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D660F2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-18 21:12:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1D660F2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-19 23:33:19  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-19 23:33:19  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-19 23:33:19  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-19 23:33:19  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-19 23:33:19  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-19 23:33:27  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D343B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-19 23:33:30  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3AFE)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-19 23:33:30  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D3AFE)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-19 23:33:30  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-19 23:33:30  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 18:34:32  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-20 18:34:32  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-20 18:34:32  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-20 18:34:32  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-20 18:34:32  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-20 18:34:39  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5126)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-20 18:34:39  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1D5126)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-20 18:34:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1D4C65)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-20 18:34:39  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-20 18:34:39  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 18:45:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x48D334)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 18:45:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x48D334)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 19:17:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xCE2712)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 19:17:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xCE2712)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 19:49:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x124BB20)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 19:49:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x124BB20)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 20:21:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x17DBEB5)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 20:21:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x17DBEB5)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 20:53:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1AFB2A4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 20:53:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1AFB2A4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 21:16:21  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E92F6E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-20 21:16:21  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 21:25:45  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2206C18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-20 21:25:45  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2206C18)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 21:26:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2207426)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-20 21:26:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 21:36:22  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2210A7B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-20 21:36:22  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 21:46:23  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2219CAF)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   9          2008-03-20 21:46:23  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-20 21:52:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2207426)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 21:52:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1E92F6E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 21:52:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2219CAF)     Logon Type: 3    
    Security     Audit Success   2          2008-03-20 21:52:46  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x2210A7B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-21 17:41:45  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 540     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-21 17:41:45  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-21 17:41:45  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 540     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-21 17:41:45  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-21 17:41:45  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-21 17:41:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x193FBE)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-21 17:41:55  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1961E3)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 540     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-21 17:41:55  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x1961E3)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-21 17:41:55  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 540    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-21 17:41:55  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-24 17:42:08  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-24 17:42:08  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-24 17:42:08  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-24 17:42:08  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-24 17:42:08  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-24 17:42:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x153B18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-24 17:42:21  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x155EF7)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-24 17:42:21  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x155EF7)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-24 17:42:21  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-24 17:42:21  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-24 17:43:26  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x175836)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-24 17:43:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x175836)     Logon Type: 3    
    Security     Audit Success   2          2008-03-24 18:03:34  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x888E75)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-24 18:03:34  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-24 18:03:36  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x889684)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-24 18:03:44  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x889684)     Logon Type: 3    
    Security     Audit Success   2          2008-03-24 18:11:09  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x888E75)     Logon Type: 3    
    Security     Audit Success   2          2008-03-24 18:15:27  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xDDA3C7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-24 18:15:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xDDA3C7)     Logon Type: 3    
    Security     Audit Success   2          2008-03-24 18:47:27  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x13FA369)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-24 18:47:27  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x13FA369)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 09:34:36  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 09:34:36  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-26 09:34:36  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 09:34:36  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-26 09:34:36  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 09:34:44  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x133405)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 09:34:47  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13547D)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 468     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 09:34:47  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13547D)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-26 09:34:47  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 468    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-26 09:34:47  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-26 09:36:51  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x165455)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 09:36:51  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x165455)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 10:08:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xBB5B25)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 10:08:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xBB5B25)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 10:40:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1583DA4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 10:40:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1583DA4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 11:12:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x19207B9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 11:12:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x19207B9)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 11:44:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1FD5941)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 11:44:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1FD5941)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 12:16:52  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x26E513D)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 12:16:52  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x26E513D)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 12:48:53  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x2A817B2)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 12:48:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x2A817B2)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 13:20:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x313F8B4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 13:20:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x313F8B4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 13:52:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x3CEA20F)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 13:52:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3CEA20F)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 14:24:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x4791D21)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 14:24:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x4791D21)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 14:56:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5035997)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 14:56:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5035997)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 15:28:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5AD4469)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 15:28:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5AD4469)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:00:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5E9BD13)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:00:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5E9BD13)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:12:55  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5ECB453)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-26 16:12:55  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-26 16:12:56  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5ECFAA1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:13:05  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5ECFAA1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:13:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5F12573)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:13:32  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5F12573)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:13:32  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x5F12698)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:13:33  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x5F12698)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:17:02  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6096076)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:17:11  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6096076)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:32:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x63E7AF4)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 16:32:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x63E7AF4)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 16:39:41  Christoph Weber                 Security                        538: User Logoff:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x5ECB453)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 17:04:54  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x6A3F6BA)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 17:04:54  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x6A3F6BA)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 21:16:03  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x951E0E9)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-26 21:16:03  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x951E0E9)     Logon Type: 3    
    Security     Audit Success   2          2008-03-26 21:36:58  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 21:36:58  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-26 21:36:58  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 21:36:58  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-26 21:36:58  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 21:37:05  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x155C9D)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 528     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 21:37:05  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x155C9D)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-26 21:37:05  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x154902)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-26 21:37:05  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 528    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-26 21:37:05  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-28 17:43:20  LOCAL SERVICE                   Security                        528: Successful Logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-28 17:43:20  LOCAL SERVICE                   Security                        576: Special privileges assigned to new logon:     User Name: LOCAL SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E5)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-28 17:43:20  NETWORK SERVICE                 Security                        528: Successful Logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name:      Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-28 17:43:20  NETWORK SERVICE                 Security                        576: Special privileges assigned to new logon:     User Name: NETWORK SERVICE     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E4)     Privileges: SeAuditPrivilege     SeAssignPrimaryTokenPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-28 17:43:20  SYSTEM                          Security                        528: Successful Logon:     User Name: SYSTEM     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x3E7)     Logon Type: 0     Logon Process: -     Authentication Package: -     Workstation Name: -     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: 4     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-28 17:43:28  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13528C)     Logon Type: 5     Logon Process: Advapi       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 464     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-28 17:43:28  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x13528C)     Privileges: SeImpersonatePrivilege     SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege  
    Security     Audit Success   2          2008-03-28 17:43:28  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x133CB7)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name:      Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: -     Source Port: -    
    Security     Audit Success   2          2008-03-28 17:43:28  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 464    Source Network Address: -    Source Port: -    
    Security     Audit Success   9          2008-03-28 17:43:28  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-28 17:45:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x160805)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-28 17:45:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x160805)     Logon Type: 3    
    Security     Audit Success   2          2008-03-28 18:17:38  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0xD08649)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-28 18:17:38  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0xD08649)     Logon Type: 3    
    Security     Audit Success   2          2008-03-28 18:49:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x1101F2E)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-28 18:49:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x1101F2E)     Logon Type: 3    
    Security     Audit Success   2          2008-03-28 19:21:39  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x18DC328)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-28 19:21:39  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x18DC328)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 09:39:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x94BEB00)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 09:39:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x94BEB00)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 10:11:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9BBC24B)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 10:11:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9BBC24B)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 10:43:17  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F1B9D1)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 10:43:17  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F1B9D1)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 10:45:20  Christoph Weber                 Security                        540: Successful Network Logon:     User Name: Christoph Weber     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9F1DB34)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   9          2008-03-29 10:45:20  Christoph Weber                 Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Christoph Weber    Source Workstation: BIER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-29 10:45:22  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F1DC18)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 10:45:31  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F1DC18)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 10:52:36  Administrator                   Security                        528: Successful Logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9F31E32)     Logon Type: 10     Logon Process: User32       Authentication Package: Negotiate     Workstation Name: WEBERSERVER     Logon GUID: -     Caller User Name: WEBERSERVER$     Caller Domain: WORLDWIDEWEBER     Caller Logon ID: (0x0,0x3E7)     Caller Process ID: 3908     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 1782    
    Security     Audit Success   2          2008-03-29 10:52:36  Administrator                   Security                        576: Special privileges assigned to new logon:     User Name: Administrator     Domain:  WEBERSERVER     Logon ID:  (0x0,0x9F31E32)     Privileges: SeSecurityPrivilege     SeBackupPrivilege     SeRestorePrivilege     SeTakeOwnershipPrivilege     SeDebugPrivilege     SeSystemEnvironmentPrivilege     SeLoadDriverPrivilege     SeImpersonatePrivilege  
    Security     Audit Success   2          2008-03-29 10:52:36  SYSTEM                          Security                        552: Logon attempt using explicit credentials:    Logged on user:     User Name: WEBERSERVER$     Domain:  WORLDWIDEWEBER     Logon ID:  (0x0,0x3E7)     Logon GUID: -    User whose credentials were used:     Target User Name: Administrator     Target Domain: WEBERSERVER     Target Logon GUID: -      Target Server Name: localhost    Target Server Info: localhost    Caller Process ID: 3908    Source Network Address: 192.168.0.2    Source Port: 1782    
    Security     Audit Success   9          2008-03-29 10:52:36  Administrator                   Security                        680: Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0    Logon account: Administrator    Source Workstation: WEBERSERVER    Error Code: 0x0    
    Security     Audit Success   2          2008-03-29 10:55:58  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F561D3)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 10:56:08  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F561D3)     Logon Type: 3    
    Security     Audit Success   2          2008-03-29 10:56:08  ANONYMOUS LOGON                 Security                        540: Successful Network Logon:     User Name:      Domain:       Logon ID:  (0x0,0x9F5B456)     Logon Type: 3     Logon Process: NtLmSsp      Authentication Package: NTLM     Workstation Name: BIER     Logon GUID: -     Caller User Name: -     Caller Domain: -     Caller Logon ID: -     Caller Process ID: -     Transited Services: -     Source Network Address: 192.168.0.2     Source Port: 0    
    Security     Audit Success   2          2008-03-29 10:56:18  ANONYMOUS LOGON                 Security                        538: User Logoff:     User Name: ANONYMOUS LOGON     Domain:  NT AUTHORITY     Logon ID:  (0x0,0x9F5B456)     Logon Type: 3    
    System       Information     None       2008-01-14 12:46:39                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-14 12:46:47                                  EventLog                        6008: The previous system shutdown at 12:37:09 PM on 1/14/2008 was unexpected.  
    System       Information     None       2008-01-14 12:46:47                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 12:46:47                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 12:46:48                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 12:46:57                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-14 12:46:57                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-14 12:46:58                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-14 12:47:01                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-14 12:47:02                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-14 12:47:02                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-14 12:47:03                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-14 20:32:15                                  Serial                          2: While validating that \Device\Serial0 was really a serial port, a fifo was detected. The fifo will be used.  
    System       Information     None       2008-01-14 20:32:22                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 20:32:22                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 20:32:23                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 20:33:55                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ROOT\DMIO\0000     Vetoing device: Root\dmio\0000     Vetoing service name: Driver\dmio     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:33:56                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: STORAGE\VOLUME\1&30A96598&0&SIGNATUREC580DBF6OFFSET7E00LENGTH500146800     Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureC580DBF6Offset7E00Length500146800     Vetoing service name: FileSystem\Ntfs     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:33:57                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\FIXEDBUTTON\2&DABA3FF&0     Vetoing device: ACPI\FixedButton\2&daba3ff&0     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:33:58                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\PNP0C0B\2&DABA3FF&0     Vetoing device: ACPI\PNP0C0B\2&daba3ff&0     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:33:59                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\PNP0C0C\2&DABA3FF&0     Vetoing device: ACPI\PNP0C0C\2&daba3ff&0     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:00                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\THERMALZONE\THRM     Vetoing device: ACPI\ThermalZone\THRM     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:02                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\PNP0F13\3&61AAA01&0     Vetoing device: ACPI\PNP0F13\3&61aaa01&0     Vetoing service name: Driver\i8042prt     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:03                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\PNP0303\3&61AAA01&0     Vetoing device: ACPI\PNP0303\3&61aaa01&0     Vetoing service name: Driver\i8042prt     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:10                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: PCI\VEN_1002&DEV_438D&SUBSYS_00000000&REV_00\3&61AAA01&0&A3     Vetoing device: ACPI\PNP0B00\4&2c4c3b2a&0     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:27                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: PCI\VEN_1002&DEV_4380&SUBSYS_81EF1043&REV_00\3&61AAA01&0&90     Vetoing device: IDE\DiskWDC_WD5000AACS-00ZUB0___________________01.01B01\5&88b39e1&0&0.0.0     Vetoing service name: Driver\Disk     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:31                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: PCIIDE\IDECHANNEL\4&120437D8&0&0     Vetoing device: IDE\DiskWDC_WD5000AACS-00ZUB0___________________01.01B01\5&88b39e1&0&0.0.0     Vetoing service name: Driver\Disk     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:42                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\PNP0B00\4&2C4C3B2A&0     Vetoing device: ACPI\PNP0B00\4&2c4c3b2a&0     Vetoing service name: Driver\ACPI     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 20:34:51                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: IDE\DISKWDC_WD5000AACS-00ZUB0___________________01.01B01\5&88B39E1&0&0.0.0     Vetoing device: IDE\DiskWDC_WD5000AACS-00ZUB0___________________01.01B01\5&88b39e1&0&0.0.0     Vetoing service name: Driver\Disk     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-14 21:07:03                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-14 21:07:03                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Warning         None       2008-01-14 21:07:03                                  W32Time                         52: The time service has set the time with offset -32549 seconds.  
    System       Information     None       2008-01-14 21:07:08                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-14 21:13:39                                  Application Popup               26: Application popup: Windows : Other people are logged on to this computer. Shutting down Windows might cause them to lose data.    Do you want to continue shutting down?  
    System       Information     None       2008-01-14 21:13:48                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-14 21:16:18                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-14 21:16:24                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 21:16:24                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 21:16:24                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 21:16:34                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-14 21:16:34                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-14 21:16:34                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-14 21:16:37                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-14 21:16:37                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-14 21:16:38                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021)  
    System       Information     8          2008-01-14 21:18:18                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Security Update for Windows Server 2003 (KB941568)  
    System       Information     8          2008-01-14 21:18:21                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Security Update for Windows Server 2003 (KB941568) - Security Update for Windows Server 2003 (KB930178)  
    System       Information     8          2008-01-14 21:18:21                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Security Update for Windows Server 2003 (KB941568) - Security Update for Windows Server 2003 (KB930178) - Security Update for Windows Server 2003 (KB935840)  
    System       Information     None       2008-01-14 21:33:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-14 21:33:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-14 21:47:02  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB942763 was installed.  
    System       Information     8          2008-01-14 21:47:07                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Server 2003 (KB942763)  
    System       Information     None       2008-01-14 21:47:08  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB927891 was installed.  
    System       Information     None       2008-01-14 21:47:13  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB938127 was installed.  
    System       Information     8          2008-01-14 21:47:13                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Server 2003 (KB927891)  
    System       Information     8          2008-01-14 21:47:18                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB938127)  
    System       Information     None       2008-01-14 21:47:20  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB931784 was installed.  
    System       Information     None       2008-01-14 21:47:40  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB933854 was installed.  
    System       Information     8          2008-01-14 21:47:42                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB931784)  
    System       Information     8          2008-01-14 21:47:47                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854)  
    System       Information     None       2008-01-14 21:47:56  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB941569 was installed.  
    System       Information     8          2008-01-14 21:48:01                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB941569)  
    System       Information     None       2008-01-14 21:48:02  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB924667-v2 was installed.  
    System       Information     8          2008-01-14 21:48:07                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB924667)  
    System       Information     None       2008-01-14 21:48:11  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB942615 was installed.  
    System       Information     8          2008-01-14 21:48:16                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615)  
    System       Information     None       2008-01-14 21:48:17  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB925902 was installed.  
    System       Information     8          2008-01-14 21:48:22                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB925902)  
    System       Information     None       2008-01-14 21:48:28  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB936021 was installed.  
    System       Information     8          2008-01-14 21:48:33                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB936021)  
    System       Information     None       2008-01-14 21:48:44  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB941568 was installed.  
    System       Information     8          2008-01-14 21:48:49                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB941568)  
    System       Information     None       2008-01-14 21:48:51  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB930178 was installed.  
    System       Information     8          2008-01-14 21:48:54                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB930178)  
    System       Information     None       2008-01-14 21:48:57  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB935840 was installed.  
    System       Information     8          2008-01-14 21:49:02                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB935840)  
    System       Information     8          2008-01-14 21:49:02                                  Windows Update Agent            21: Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates:  - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB942615) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Security Update for Windows Server 2003 (KB941568) - Security Update for Windows Server 2003 (KB930178) - Security Update for Windows Server 2003 (KB935840)  
    System       Information     None       2008-01-14 21:49:13                                  Application Popup               26: Application popup: Windows : Other people are logged on to this computer. Restarting Windows might cause them to lose data.    Do you want to continue restarting?  
    System       Information     None       2008-01-14 21:49:21                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-14 21:50:01                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-14 21:50:09                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 21:50:09                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 21:50:09                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 21:50:19                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-14 21:50:19                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-14 21:50:19                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-14 21:50:23                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-14 21:50:23                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-14 21:50:24                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-14 21:51:57                                  Workstation                     3261: This computer has been successfully joined to workgroup 'WORLDWIDEWEBER'.  
    System       Information     None       2008-01-14 21:52:03                                  Application Popup               26: Application popup: Windows : Other people are logged on to this computer. Restarting Windows might cause them to lose data.    Do you want to continue restarting?  
    System       Information     None       2008-01-14 21:52:11                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-14 21:52:52                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-14 21:53:00                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 21:53:00                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 21:53:00                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 21:53:09                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-14 21:53:09                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-14 21:53:09                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-14 21:53:12                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-14 21:53:13                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-14 21:53:13                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-14 22:20:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-14 22:20:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-14 22:41:29                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-14 22:46:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-14 22:46:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-14 23:16:27                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-14 23:16:27                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-14 23:16:32                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-14 23:53:22  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x80000000    Shutdown Type: restart    Comment:   
    System       Information     None       2008-01-14 23:53:23                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-14 23:54:32                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-14 23:54:35                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-14 23:54:35                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-14 23:54:36                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-14 23:54:44                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-14 23:54:45                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-14 23:54:45                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-14 23:54:48                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-14 23:54:49                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-14 23:54:49                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Warning         None       2008-01-15 00:03:50                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-15 00:03:50                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-15 00:03:50                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-15 00:03:50                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Information     None       2008-01-15 00:05:44                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-15 00:05:44                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-15 00:47:43                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Warning         None       2008-01-15 00:47:43                                  W32Time                         52: The time service has set the time with offset 43226 seconds.  
    System       Error           None       2008-01-15 00:49:07                                  Virtual Disk Service            10: Unexpected provider failure. Restarting the service may fix the problem. Error code: 8000FFFF@020A0008  
    System       Warning         None       2008-01-15 00:49:07                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 00:49:07                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 00:49:07                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 00:49:07                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 00:49:07                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         2          2008-01-15 00:49:07                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Information     None       2008-01-15 03:22:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-15 03:22:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Warning         2          2008-01-15 03:30:33                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Warning         2          2008-01-15 03:30:33                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Information     None       2008-01-15 04:35:38                                  EventLog                        6011: The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to WEBERSERVER.  
    System       Information     None       2008-01-15 04:35:45                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 04:40:09  SYSTEM                          NtServicePack                   4377: Windows Server 2003 Hotfix KB937108-v2 was installed.  
    System       Information     None       2008-01-15 04:40:15  SYSTEM                          NtServicePack                   4377: Windows Server 2003 Hotfix KB936598-v2 was installed.  
    System       Information     None       2008-01-15 04:40:21  SYSTEM                          NtServicePack                   4377: Windows Server 2003 Hotfix KB937253-v2 was installed.  
    System       Information     None       2008-01-15 04:40:26  SYSTEM                          NtServicePack                   4377: Windows Server 2003 Hotfix KB937153-v2 was installed.  
    System       Error           None       2008-01-15 04:42:44                                  Setup                           60055: Windows Setup encountered non-fatal errors during installation. Please check the setuperr.log found in your Windows directory for more information.
    System       Information     None       2008-01-15 04:42:44                                  Setup                           60054: Setup successfully installed Windows build 3790.
    System       Information     None       2008-01-15 04:42:46                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 04:42:46  SYSTEM                          USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned)    Reason Code: 0x80020003    Shutdown Type: restart    Comment: Windows setup has completed, and the computer must restart.  
    System       Information     None       2008-01-15 04:43:40                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 04:43:47                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 04:43:47                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 04:43:48                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 04:43:54                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 04:43:55                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 04:43:55                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 04:44:02                                  SBCore                          1016: A new license store for the client access licenses was created.  
    System       Information     None       2008-01-15 04:44:14                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 04:44:27  Administrator                   USER32                          1074: The process qs.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x80020004    Shutdown Type: restart    Comment:   
    System       Information     None       2008-01-15 04:44:33                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 04:47:33                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 04:47:39                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 04:47:39                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 04:47:39                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 04:47:41                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 04:47:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 04:47:42                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 04:48:12  Administrator                   USER32                          1074: The process qs.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x80020004    Shutdown Type: restart    Comment:   
    System       Information     None       2008-01-15 04:48:15                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 04:49:03                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 04:49:09                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 04:49:09                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 04:49:09                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 04:49:11                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 04:49:12                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 04:49:12                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 04:51:38  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix ummsglog was installed.  
    System       Information     None       2008-01-15 04:51:57  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB917013 was installed.  
    System       Information     None       2008-01-15 04:52:58                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 04:53:07  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umqsm was installed.  
    System       Information     None       2008-01-15 04:53:26  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umde was installed.  
    System       Information     None       2008-01-15 04:53:27                                  Virtual Disk Service            4: Service stopped.  
    System       Information     None       2008-01-15 04:53:27                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 04:53:38  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umcenroll was installed.  
    System       Information     None       2008-01-15 04:53:43  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umcenrollid was installed.  
    System       Information     None       2008-01-15 04:53:48  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umcenrollsetup was installed.  
    System       Information     None       2008-01-15 04:53:56  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umconnector was installed.  
    System       Information     None       2008-01-15 04:54:06  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umconsole was installed.  
    System       Information     None       2008-01-15 04:54:11                                  HTTP                            15007: Reservation for namespace identified by URL prefix http://*:2869/ was successfully added.  
    System       Information     None       2008-01-15 04:54:15                                  WMConnectCDS                    14200: 'WMConnectCDS' service has been installed.  
    System       Information     None       2008-01-15 04:54:15                                  HTTP                            15007: Reservation for namespace identified by URL prefix http://+:10243/WMCv2/ was successfully added.  
    System       Information     None       2008-01-15 04:54:23  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umupnp was installed.  
    System       Information     None       2008-01-15 04:54:29                                  Virtual Disk Service            4: Service stopped.  
    System       Information     None       2008-01-15 04:54:29                                  Virtual Disk Service            3: Service started.  
    System       Error           None       2008-01-15 04:55:00                                  DCOM                            10010: The server {4FB6BB00-3347-11D0-B40A-00AA005FF586} did not register with DCOM within the required timeout.  
    System       Error           None       2008-01-15 04:55:00                                  VDS Dynamic Provider 1.1        1: The provider failed to load. Error(8004241B).  
    System       Error           None       2008-01-15 04:55:00                                  Virtual Disk Service            17: VDS fails to launch provider {F96544E6-5C8D-47B9-AA6E-FD19AB278629}. Error code: 8004241B@02000012  
    System       Information     None       2008-01-15 04:55:00                                  Virtual Disk Service            4: Service stopped.  
    System       Information     None       2008-01-15 04:55:01                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 04:55:11  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umoobe was installed.  
    System       Information     None       2008-01-15 04:55:22  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umnotify was installed.  
    System       Information     None       2008-01-15 04:55:27  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umas was installed.  
    System       Information     None       2008-01-15 04:55:31  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umcp was installed.  
    System       Information     None       2008-01-15 04:55:36  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umpsdk was installed.  
    System       Information     None       2008-01-15 04:55:38                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 04:55:42  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umpcbackup was installed.  
    System       Information     None       2008-01-15 04:55:47  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umrahome was installed.  
    System       Information     None       2008-01-15 04:55:53  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umraremote was installed.  
    System       Information     None       2008-01-15 04:56:00  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umrabase was installed.  
    System       Information     None       2008-01-15 04:56:12  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umwhsarch was installed.  
    System       Information     None       2008-01-15 04:56:18  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umddns was installed.  
    System       Information     None       2008-01-15 04:56:24  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix umpf was installed.  
    System       Information     None       2008-01-15 04:56:43  Administrator                   USER32                          1074: The process qs.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x80020004    Shutdown Type: restart    Comment:   
    System       Information     None       2008-01-15 04:56:47                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 04:57:30                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 04:57:37                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 04:57:37                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 04:57:37                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 04:57:38                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 04:57:38                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 04:57:38                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 04:57:39                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 04:57:42                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 05:03:18  Administrator                   NtServicePack                   4382: Windows Server 2003 KB917013 was removed from your computer, and the previous Windows Server 2003 configuration was restored.  
    System       Information     None       2008-01-15 05:09:49                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 05:10:07                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 05:22:12                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 05:22:17                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 05:22:17                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 05:22:17                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 05:22:18                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 05:22:18                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 05:22:18                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 05:22:19                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 05:22:20                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 05:22:21                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 05:32:59                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 05:36:10                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 05:36:19                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 05:36:19                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 05:36:19                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 05:36:20                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 05:36:20                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 05:36:20                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 05:36:20                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 05:36:21                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 05:36:21                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 05:37:41                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-15 05:37:50                                  EventLog                        6008: The previous system shutdown at 8:36:19 PM on 1/14/2008 was unexpected.  
    System       Information     None       2008-01-15 05:37:50                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 05:37:50                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 05:37:50                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 05:37:51                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 05:37:51                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 05:37:51                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 05:37:51                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 05:37:52                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 05:37:54                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Error           None       2008-01-15 05:52:58  NETWORK SERVICE                 DCOM                            10016: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID   {BA126AD1-2166-11D1-B1D0-00805FC1270E}   to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20).  This security permission can be modified using the Component Services administrative tool.  
    System       Error           None       2008-01-15 05:53:01                                  W32Time                         17: Time Provider NtpClient: An error occurred during DNS lookup of the manually  configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15  minutes.  The error was: A socket operation was attempted to an unreachable host. (0x80072751)  
    System       Error           None       2008-01-15 05:53:01                                  W32Time                         29: The time provider NtpClient is configured to acquire time from one or more  time sources, however none of the sources are currently accessible.   No attempt to contact a source will be made for 15 minutes.  NtpClient has no source of accurate time.   
    System       Information     8          2008-01-15 05:54:31                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Automatic Updates  
    System       Information     8          2008-01-15 05:55:40                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 12:00 AM:  - Security Update for Windows Server 2003 (KB944653)  
    System       Information     8          2008-01-15 05:55:59                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 12:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914)  
    System       Information     8          2008-01-15 05:57:10                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365)  
    System       Information     8          2008-01-15 05:57:19                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891)  
    System       Information     8          2008-01-15 05:57:19                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398)  
    System       Information     8          2008-01-15 05:57:27                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127)  
    System       Information     8          2008-01-15 05:57:52                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784)  
    System       Information     8          2008-01-15 05:58:11                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854)  
    System       Information     8          2008-01-15 05:58:11                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569)  
    System       Information     8          2008-01-15 05:58:23                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667)  
    System       Information     8          2008-01-15 05:58:40                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902)  
    System       Information     8          2008-01-15 05:58:40                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021)  
    System       Information     8          2008-01-15 05:59:25                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021)  
    System       Information     8          2008-01-15 05:59:35                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)  
    System       Information     8          2008-01-15 05:59:35                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)  
    System       Information     8          2008-01-15 05:59:42                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)  
    System       Information     8          2008-01-15 05:59:42                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)  
    System       Information     8          2008-01-15 05:59:42                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server 2003 (KB929123)  
    System       Information     8          2008-01-15 05:59:52                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 05:59:52                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Update for Windows Server 2003 (KB936021) - Cumulative Se  
    System       Information     8          2008-01-15 05:59:52                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Update for Windows Server 2003 (KB925902) - Security Upda  
    System       Information     8          2008-01-15 05:59:52                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Update for Windows Server 2003 (KB924667) - Security Upda  
    System       Information     8          2008-01-15 05:59:56                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Update for Windows Server 2003 (KB941569) - Security Upda  
    System       Information     8          2008-01-15 06:00:01                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB933854) - Security Upda  
    System       Information     8          2008-01-15 06:00:01                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Microsoft .NET Framework, Version 1  
    System       Information     8          2008-01-15 06:00:01                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 06:00:06                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 06:00:06                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 06:00:06                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 06:00:11                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     8          2008-01-15 06:01:46                                  Windows Update Agent            18: Installation Ready: The following updates are downloaded and ready for installation. This computer is currently scheduled to install these updates on ?Tuesday, ?January ?15, ?2008 at 4:00 AM:  - Security Update for Windows Server 2003 (KB933729) - Security Update for Windows Server 2003 (KB935839) - Update for Windows Server 2003 (KB942840) - Security Update for Windows Server 2003 (KB944653) - Security Update for Windows Server 2003 (KB932168) - Security Update for Windows Server 2003 (KB936782) - Security Update for Windows Server 2003 (KB941644) - Security Update for Windows Server 2003 (KB943485) - Security Update for Windows Server 2003 (KB926122) - Update for Windows Home Server (KB941914) - Security Update for Windows Server 2003 (KB921503) - Security Update for Microsoft .NET Framework, Version 2.0 (KB928365) - Security Update for Windows Server 2003 (KB943460) - Update for Windows Server 2003 (KB942763) - Update for Windows Server 2003 (KB927891) - Security Update for Windows Media Player 6.4 (KB925398) - Security Update for Windows Server 2003 (KB938127) - Security Update for Windows Server 2003 (KB931784) - Security Update for Outlook Express for Windows Server   
    System       Information     None       2008-01-15 06:03:19  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB933729 was installed.  
    System       Information     8          2008-01-15 06:03:24                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB933729)  
    System       Information     None       2008-01-15 06:03:25  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB935839 was installed.  
    System       Information     None       2008-01-15 06:03:31  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB942840 was installed.  
    System       Information     8          2008-01-15 06:03:31                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB935839)  
    System       Information     None       2008-01-15 06:03:37  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB944653 was installed.  
    System       Information     8          2008-01-15 06:03:37                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Server 2003 (KB942840)  
    System       Information     8          2008-01-15 06:03:43                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB944653)  
    System       Information     None       2008-01-15 06:03:44  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB932168 was installed.  
    System       Information     8          2008-01-15 06:03:49                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB932168)  
    System       Information     None       2008-01-15 06:03:50  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB936782 was installed.  
    System       Information     None       2008-01-15 06:03:56  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB941644 was installed.  
    System       Information     8          2008-01-15 06:03:56                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB936782)  
    System       Information     8          2008-01-15 06:04:01                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB941644)  
    System       Information     None       2008-01-15 06:04:02  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB943485 was installed.  
    System       Information     8          2008-01-15 06:04:07                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB943485)  
    System       Information     None       2008-01-15 06:04:08  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB926122 was installed.  
    System       Information     8          2008-01-15 06:04:13                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB926122)  
    System       Information     None       2008-01-15 06:04:14  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix KB941914 was installed.  
    System       Information     8          2008-01-15 06:04:19                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Home Server (KB941914)  
    System       Information     None       2008-01-15 06:04:20  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB921503 was installed.  
    System       Information     8          2008-01-15 06:04:26                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB921503)  
    System       Information     None       2008-01-15 06:04:39                                  WMConnectCDS                    14203: Service 'WMConnectCDS' stopped.  
    System       Information     None       2008-01-15 06:05:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 06:05:47                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 06:08:53                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-15 06:09:01                                  EventLog                        6008: The previous system shutdown at 9:05:50 PM on 1/14/2008 was unexpected.  
    System       Error           None       2008-01-15 06:09:01                                  Dhcp                            1002: The IP address lease 192.168.0.3 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Information     None       2008-01-15 06:09:01                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 06:09:01                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 06:09:01                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 06:09:12                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 06:09:13                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 06:09:13                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 06:09:16                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 06:09:16                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 06:09:16                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 06:09:17                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-15 08:31:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-15 08:31:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-15 08:47:22                                  Application Popup               26: Application popup: Windows - Delayed Write Failed : Windows was unable to save all the data for the file E:\$Mft. The data has been lost. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.   
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Ntfs                            50: {Delayed Write Failed}  Windows was unable to save all the data for the file . The data has been lost.  This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Ntfs                            50: {Delayed Write Failed}  Windows was unable to save all the data for the file . The data has been lost.  This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Warning         None       2008-01-15 08:47:22                                  Disk                            51: An error was detected on device \Device\Harddisk1 during a paging operation.  
    System       Information     None       2008-01-15 08:47:23                                  Application Popup               26: Application popup: Windows - Delayed Write Failed : Windows was unable to save all the data for the file E:\$Mft. The data has been lost. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.   
    System       Warning         None       2008-01-15 08:47:23                                  Ntfs                            50: {Delayed Write Failed}  Windows was unable to save all the data for the file . The data has been lost.  This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere.  
    System       Warning         2          2008-01-15 08:47:23                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Warning         2          2008-01-15 08:47:23                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Warning         2          2008-01-15 10:50:38                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Information     None       2008-01-15 18:36:38                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-15 18:37:10                                  EventLog                        6008: The previous system shutdown at 6:33:15 PM on 1/15/2008 was unexpected.  
    System       Information     None       2008-01-15 18:37:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 18:37:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 18:37:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 18:37:20                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 18:37:20                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 18:37:20                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 18:37:23                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 18:37:24                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 18:37:31                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 19:11:38                                  Application Popup               26: Application popup: Windows : If you shut down this remote computer, no one can use it until someone at the remote location manually restarts it.    Do you want to continue shutting down?  
    System       Information     None       2008-01-15 19:11:48                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-15 20:05:33                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-15 20:05:44                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-15 20:05:44                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-15 20:05:45                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-15 20:05:54                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-15 20:05:54                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-15 20:05:54                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-15 20:05:57                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-15 20:05:58                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-15 20:05:59                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-15 20:06:11                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: IDE\DISKMAXTOR_6L250S0__________________________BACE1G10\354C393938344733202020202020202020202020     Vetoing device: STORAGE\Volume\1&30a96598&0&SignatureC1312D31Offset7E00Length3A388A8400     Vetoing service name: FileSystem\Ntfs     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Warning         2          2008-01-15 20:09:24                                  Ftdisk                          57: The system failed to flush data to the transaction log. Corruption may occur.  
    System       Information     None       2008-01-15 20:24:02                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 21:45:16                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 21:49:26                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 21:51:38                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-15 21:51:39                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-15 21:51:43                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Error           None       2008-01-15 21:51:48                                  Dhcp                            1002: The IP address lease 192.168.0.11 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Warning         None       2008-01-15 21:52:52                                  Dhcp                            1007: Your computer has automatically configured the IP address for the Network  Card with network address 001D602D2664.  The IP address being used is 169.254.24.131.  
    System       Information     None       2008-01-15 21:55:03                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-15 21:55:03                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-15 21:55:08                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Warning         None       2008-01-15 21:56:09                                  Dhcp                            1007: Your computer has automatically configured the IP address for the Network  Card with network address 001D602D2664.  The IP address being used is 169.254.24.131.  
    System       Information     None       2008-01-15 22:02:58                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-15 22:02:58                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-15 22:04:23                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 22:08:22                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 22:08:30                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Warning         None       2008-01-15 22:08:30                                  Dhcp                            1003: Your computer was not able to renew its address from the network (from the  DHCP Server) for the Network Card with network address 001D602D2664.  The following  error occurred:   The operation was canceled by the user.  .  Your computer will continue to try and obtain an address on its own from  the network address (DHCP) server.  
    System       Information     None       2008-01-15 22:12:26                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 22:12:50                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-15 22:14:18                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-15 22:14:18                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-15 22:14:23                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Error           None       2008-01-15 22:14:35                                  Dhcp                            1002: The IP address lease 192.168.0.3 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Information     None       2008-01-15 22:15:52                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Error           None       2008-01-15 22:36:15                                  Dhcp                            1002: The IP address lease 192.168.0.3 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Information     None       2008-01-15 22:36:15                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-15 23:12:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-15 23:12:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-16 12:00:00                                  EventLog                        6013: The system uptime is 57279 seconds.  
    System       Information     None       2008-01-16 16:27:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-16 16:27:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-16 19:01:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-16 19:01:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Warning         None       2008-01-16 20:05:58                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-01-17 03:17:05                                  W3SVC                           1074: A worker process with process id of '276' serving application pool 'DefaultAppPool' has requested a recycle because the worker process reached its allowed processing time limit.    
    System       Information     None       2008-01-17 09:42:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-17 09:42:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-17 12:00:00                                  EventLog                        6013: The system uptime is 143679 seconds.  
    System       Information     None       2008-01-17 14:51:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-17 14:51:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-17 18:21:17                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:21:25                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Warning         None       2008-01-17 18:21:25                                  Dhcp                            1003: Your computer was not able to renew its address from the network (from the  DHCP Server) for the Network Card with network address 001D602D2664.  The following  error occurred:   The operation was canceled by the user.  .  Your computer will continue to try and obtain an address on its own from  the network address (DHCP) server.  
    System       Information     None       2008-01-17 18:22:08                                  Tcpip                           4202: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was disconnected from the network,  and the adapter's network configuration has been released. If the network  adapter was not disconnected, this may indicate that it has malfunctioned.  Please contact your vendor for updated drivers.  
    System       Information     None       2008-01-17 18:22:08                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-17 18:22:13                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:23:45                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:23:53                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Warning         None       2008-01-17 18:23:53                                  Dhcp                            1003: Your computer was not able to renew its address from the network (from the  DHCP Server) for the Network Card with network address 001D602D2664.  The following  error occurred:   The operation was canceled by the user.  .  Your computer will continue to try and obtain an address on its own from  the network address (DHCP) server.  
    System       Error           None       2008-01-17 18:24:09                                  Dhcp                            1002: The IP address lease 192.168.0.11 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Information     None       2008-01-17 18:24:09                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-17 18:26:37                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:26:57                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:30:31                                  Tcpip                           4201: The system detected that network adapter Realtek RTL8168/8111 PCI-E Gigabit Ethernet NIC was connected to the network,  and has initiated normal operation over the network adapter.  
    System       Information     None       2008-01-17 18:34:43  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x80000000    Shutdown Type: restart    Comment:   
    System       Information     None       2008-01-17 18:34:44                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-17 18:35:57                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-17 18:36:10                                  Dhcp                            1002: The IP address lease 192.168.0.3 for the Network Card with network address 001D602D2664 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).  
    System       Information     None       2008-01-17 18:36:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-17 18:36:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-17 18:36:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-17 18:36:21                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-17 18:36:21                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-17 18:36:21                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-17 18:36:25                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-17 18:36:25                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-17 18:36:26                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-17 18:52:06                                  Application Popup               26: Application popup: Windows : If you shut down this remote computer, no one can use it until someone at the remote location manually restarts it.    Do you want to continue shutting down?  
    System       Information     None       2008-01-17 18:52:16                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-19 11:46:37                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-19 11:46:49                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-19 11:46:49                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-19 11:46:49                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-19 11:46:59                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-19 11:46:59                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-19 11:46:59                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-19 11:47:03                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-19 11:47:04                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-19 11:47:06                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-19 12:00:00                                  EventLog                        6013: The system uptime is 819 seconds.  
    System       Information     None       2008-01-19 12:23:58                                  Application Popup               26: Application popup: Windows : Other people are logged on to this computer. Restarting Windows might cause them to lose data.    Do you want to continue restarting?  
    System       Information     None       2008-01-19 12:24:16                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-19 12:25:05                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-19 12:25:18                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-19 12:25:18                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-19 12:25:18                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-19 12:25:27                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-19 12:25:27                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-19 12:25:28                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-19 12:25:32                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-19 12:25:32                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-19 12:25:34                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-19 13:17:56                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-01-19 13:23:33                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-19 13:24:31                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-19 13:24:37                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-19 13:24:37                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-19 13:24:37                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-19 13:24:47                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-19 13:24:48                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-19 13:24:48                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-19 13:24:53                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-19 13:24:53                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-19 13:24:55                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-19 14:01:04                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 14:01:05                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 17:17:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-19 17:17:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-19 17:50:15                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 17:50:15                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:04:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-19 18:04:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-19 18:50:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-19 18:50:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-19 18:51:37                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:51:38                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:51:54                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:51:54                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:52:10                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-01-19 18:52:42                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Error           None       2008-01-19 18:54:09                                  VolSnap                         25: The shadow copies of volume D: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.  
    System       Error           None       2008-01-19 19:49:58                                  DCOM                            10009: DCOM was unable to communicate with the computer BIER using any of the configured  protocols.  
    System       Warning         None       2008-01-19 19:52:07                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "C:\Program Files\xplorer2_lite\xplorer2_lite.exe"  
    System       Information     None       2008-01-19 19:59:32                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-19 20:00:23                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-19 20:00:29                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-19 20:00:29                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-19 20:00:29                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-19 20:00:38                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-19 20:00:39                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-19 20:00:39                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-19 20:00:44                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-19 20:00:44                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-19 20:00:45                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-19 23:06:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-19 23:06:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-19 23:53:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-19 23:53:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-20 02:13:00                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-20 02:13:00                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-20 08:40:02                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-20 08:40:02                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-20 12:00:00                                  EventLog                        6013: The system uptime is 57595 seconds.  
    System       Information     None       2008-01-20 14:35:33                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-20 14:36:18                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-20 14:36:30                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-20 14:36:30                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-20 14:36:30                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-20 14:36:39                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-20 14:36:40                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-20 14:36:41                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-20 14:36:45                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-20 14:36:45                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-20 14:36:46                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-20 15:23:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-20 15:23:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-20 18:44:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-20 18:44:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-21 13:36:21                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-21 13:36:32                                  EventLog                        6008: The previous system shutdown at 12:06:31 AM on 1/21/2008 was unexpected.  
    System       Information     None       2008-01-21 13:36:32                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 13:36:32                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 13:36:33                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 13:36:42                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 13:36:42                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 13:36:43                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 13:36:46                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 13:36:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 13:36:48                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-21 16:22:30                                  PlugPlayManager                 271: The Plug and Play operation cannot be completed because a device driver is preventing the device from stopping. The name of the device driver is listed as the vetoing service name below.       Vetoed device: ACPI\AUTHENTICAMD_-_X86_FAMILY_15_MODEL_127\_0     Vetoing device: ACPI\AuthenticAMD_-_x86_Family_15_Model_127\_0     Vetoing service name: Driver\Processor     Veto type 6: PNP_VetoDevice       When Windows attempts to install, upgrade, remove, or reconfigure a device, it queries the driver responsible for that device to confirm that the operation can be performed. If any of these drivers denies permission (query-removal veto), then the computer must be restarted in order to complete the operation.      User Action    Restart your computer.  
    System       Information     None       2008-01-21 16:22:36                                  Application Popup               26: Application popup: Windows : Other people are logged on to this computer. Restarting Windows might cause them to lose data.    Do you want to continue restarting?  
    System       Information     None       2008-01-21 16:22:55                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-21 16:23:46                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-21 16:23:54                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 16:23:54                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 16:23:54                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 16:24:03                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 16:24:04                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 16:24:04                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 16:24:07                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 16:24:08                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 16:24:09                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-21 16:31:21                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-21 16:32:13                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-21 16:32:23                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 16:32:23                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 16:32:23                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 16:32:32                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 16:32:32                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 16:32:33                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 16:32:36                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 16:32:37                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 16:32:38                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-21 16:39:46                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-21 16:40:40                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-21 16:40:50                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 16:40:50                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 16:40:51                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 16:41:00                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 16:41:01                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 16:41:01                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 16:41:04                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 16:41:05                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 16:41:06                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-21 16:45:51                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-21 16:46:46                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-21 16:46:55                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 16:46:55                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 16:46:55                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 16:47:05                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 16:47:05                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 16:47:06                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 16:47:06                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 16:47:10                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 16:47:13                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-21 16:52:21                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-01-21 16:53:13                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-01-21 16:53:27                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-21 16:53:27                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-21 16:53:27                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-21 16:53:37                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-21 16:53:37                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-21 16:53:38                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-21 16:53:41                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-21 16:53:42                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-21 16:53:43                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-23 01:29:55                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-23 01:30:10                                  EventLog                        6008: The previous system shutdown at 7:44:27 PM on 1/21/2008 was unexpected.  
    System       Information     None       2008-01-23 01:30:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-23 01:30:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-23 01:30:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-23 01:30:19                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-23 01:30:20                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-23 01:30:20                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-23 01:30:24                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-23 01:30:24                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-23 01:30:24                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-23 01:30:25                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-23 01:30:49                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-23 18:23:45                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-23 18:24:02                                  EventLog                        6008: The previous system shutdown at 2:40:19 AM on 1/23/2008 was unexpected.  
    System       Information     None       2008-01-23 18:24:02                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-23 18:24:02                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-23 18:24:02                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-23 18:24:11                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-23 18:24:12                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-23 18:24:12                                  IPSec                           4294: The IPSec driver has entered Secure mode. IPSec policies, if they have been  configured, are now being applied to this computer.  
    System       Information     None       2008-01-23 18:24:15                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-23 18:24:16                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-23 18:24:16                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-23 18:24:17                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-23 18:24:32                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-23 20:28:01                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-23 20:28:17                                  EventLog                        6008: The previous system shutdown at 8:17:02 PM on 1/23/2008 was unexpected.  
    System       Information     None       2008-01-23 20:28:17                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-23 20:28:17                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-23 20:28:17                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-23 20:28:26                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-23 20:28:28                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-23 20:28:31                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-23 20:28:32                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-23 20:28:32                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-23 20:28:33                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-23 20:28:48                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Error           None       2008-01-24 00:01:02                                  VolSnap                         9: The flush and hold writes operation on volume C:\fs\F timed out while waiting for file system cleanup.  
    System       Information     None       2008-01-24 05:30:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-24 05:30:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-24 08:28:56                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-24 08:29:10                                  EventLog                        6008: The previous system shutdown at 6:18:20 AM on 1/24/2008 was unexpected.  
    System       Information     None       2008-01-24 08:29:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-24 08:29:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-24 08:29:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-24 08:29:20                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-24 08:29:22                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-24 08:29:25                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-24 08:29:25                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-24 08:29:25                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-24 08:29:26                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-24 08:29:41                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-24 12:00:01                                  EventLog                        6013: The system uptime is 12678 seconds.  
    System       Information     None       2008-01-24 14:10:02                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-24 14:10:02                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-01-24 23:31:06                                  DCOM                            10005: DCOM got error "%1058" attempting to start the service PortForwarding with arguments ""  in order to run the server:  {E1B866B8-D692-45AB-A065-A84C881F8AB0}  
    System       Information     None       2008-01-24 23:46:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-24 23:46:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 00:28:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 00:28:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 01:30:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 01:30:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 03:28:16                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 03:28:16                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 04:52:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 04:52:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 06:46:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 06:46:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 08:02:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 08:02:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Warning         None       2008-01-25 08:29:41                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-01-25 09:28:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 09:28:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 10:48:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 10:48:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 12:00:00                                  EventLog                        6013: The system uptime is 99077 seconds.  
    System       Information     None       2008-01-25 12:16:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 12:16:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 13:39:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 13:39:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 15:12:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 15:12:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 16:40:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 16:40:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 18:07:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 18:07:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-25 19:35:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-25 19:35:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 17:20:42                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-27 17:20:56                                  EventLog                        6008: The previous system shutdown at 9:02:28 PM on 1/25/2008 was unexpected.  
    System       Information     None       2008-01-27 17:20:56                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-27 17:20:56                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-27 17:20:56                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-27 17:21:06                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-27 17:21:07                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-27 17:21:10                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-27 17:21:11                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-27 17:21:12                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 17:21:13                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-27 17:21:31                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Warning         None       2008-01-27 17:25:25                                  PlugPlayManager                 257: Timed out sending notification of target device change to window of "LDM Service"  
    System       Information     None       2008-01-27 17:38:49                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 17:38:49                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 18:17:54                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-27 18:18:10                                  EventLog                        6008: The previous system shutdown at 6:15:01 PM on 1/27/2008 was unexpected.  
    System       Information     None       2008-01-27 18:18:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-27 18:18:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-27 18:18:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-27 18:18:19                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-27 18:18:20                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-27 18:18:23                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-27 18:18:24                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-27 18:18:25                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 18:18:26                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-27 18:18:40                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 18:36:55                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-27 18:37:10                                  EventLog                        6008: The previous system shutdown at 6:33:10 PM on 1/27/2008 was unexpected.  
    System       Information     None       2008-01-27 18:37:10                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-27 18:37:10                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-27 18:37:10                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-27 18:37:19                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-27 18:37:20                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-27 18:37:23                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-27 18:37:24                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-27 18:37:25                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 18:37:26                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-27 18:37:40                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 18:55:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 18:55:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 19:34:13                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-27 19:34:30                                  EventLog                        6008: The previous system shutdown at 7:11:10 PM on 1/27/2008 was unexpected.  
    System       Information     None       2008-01-27 19:34:30                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-27 19:34:30                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-27 19:34:30                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-27 19:34:39                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-27 19:34:40                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-27 19:34:43                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-27 19:34:44                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-27 19:34:45                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 19:34:46                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-27 19:35:00                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-27 19:52:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 19:52:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 21:28:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 21:28:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 22:59:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 22:59:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-27 23:23:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-27 23:23:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 00:49:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 00:49:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 02:39:19                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 02:39:19                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 04:23:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 04:23:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 05:43:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 05:43:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 07:05:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 07:05:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 08:19:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 08:19:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 09:45:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 09:45:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 11:25:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 11:25:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 12:00:00                                  EventLog                        6013: The system uptime is 59163 seconds.  
    System       Information     None       2008-01-28 12:45:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 12:45:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 13:53:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 13:53:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 15:04:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 15:04:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 16:43:19                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 16:43:19                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 18:30:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 18:30:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 19:33:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 19:33:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Warning         None       2008-01-28 19:35:00                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-01-28 20:26:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 20:26:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 21:48:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 21:48:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-28 23:10:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-28 23:10:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 00:45:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 00:45:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 02:16:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 02:16:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 04:07:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 04:07:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 05:41:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 05:41:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 06:49:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 06:49:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 08:28:57                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 08:28:57                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 10:10:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 10:10:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 10:30:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 10:30:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 12:00:00                                  EventLog                        6013: The system uptime is 145563 seconds.  
    System       Information     None       2008-01-29 12:09:52                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 12:09:52                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 13:57:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 13:57:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 15:30:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 15:30:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 16:10:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 16:10:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-01-29 17:05:15                                  DCOM                            10010: The server {E579AB5F-1CC4-44B4-BED9-DE0991FF0623} did not register with DCOM within the required timeout.  
    System       Information     None       2008-01-29 17:26:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 17:26:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 19:16:00                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 19:16:00                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 21:10:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 21:10:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-29 22:32:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-29 22:32:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 00:05:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 00:05:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 01:32:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 01:32:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 03:26:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 03:26:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 05:00:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 05:00:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 06:26:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 06:26:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 07:00:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 07:00:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 08:15:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 08:15:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 09:33:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 09:33:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 11:27:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 11:27:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 18:19:42                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-30 18:19:59                                  EventLog                        6008: The previous system shutdown at 11:34:30 AM on 1/30/2008 was unexpected.  
    System       Information     None       2008-01-30 18:19:59                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-30 18:19:59                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-30 18:19:59                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-30 18:20:09                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-30 18:20:10                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-30 18:20:13                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-30 18:20:14                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-30 18:20:14                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-30 18:20:15                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-30 18:20:33                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-30 18:37:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 18:37:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 19:39:11                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-30 19:39:26                                  EventLog                        6008: The previous system shutdown at 7:35:07 PM on 1/30/2008 was unexpected.  
    System       Information     None       2008-01-30 19:39:26                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-30 19:39:26                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-30 19:39:26                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-30 19:39:35                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-30 19:39:36                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-30 19:39:39                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-30 19:39:41                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-30 19:39:41                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-30 19:39:42                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-30 19:39:56                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-01-30 19:57:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 19:57:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-30 20:51:52                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-30 20:52:08                                  EventLog                        6008: The previous system shutdown at 8:49:27 PM on 1/30/2008 was unexpected.  
    System       Information     None       2008-01-30 20:52:08                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-30 20:52:08                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-30 20:52:08                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-30 20:52:17                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-30 20:52:19                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-30 20:52:22                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-30 20:52:23                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-30 20:52:23                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-30 20:52:24                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-30 20:52:39                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-30 21:09:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-30 21:09:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-31 08:18:15                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-01-31 08:18:31                                  EventLog                        6008: The previous system shutdown at 10:43:09 PM on 1/30/2008 was unexpected.  
    System       Information     None       2008-01-31 08:18:31                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-01-31 08:18:31                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-01-31 08:18:31                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-01-31 08:18:41                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-01-31 08:18:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-01-31 08:18:45                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-01-31 08:18:46                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-01-31 08:18:46                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-31 08:18:47                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-01-31 08:19:02                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-01-31 08:36:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-31 08:36:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-01-31 10:29:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-01-31 10:29:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-01-31 10:51:21                                  DCOM                            10010: The server {E579AB5F-1CC4-44B4-BED9-DE0991FF0623} did not register with DCOM within the required timeout.  
    System       Information     None       2008-02-01 17:49:39                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-01 17:49:53                                  EventLog                        6008: The previous system shutdown at 11:14:33 AM on 1/31/2008 was unexpected.  
    System       Information     None       2008-02-01 17:49:53                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-01 17:49:53                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-01 17:49:53                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-01 17:50:03                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-01 17:50:06                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-01 17:50:09                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-01 17:50:10                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-01 17:50:10                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-01 17:50:11                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-01 17:50:26                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-01 18:07:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-01 18:07:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-01 19:59:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-01 19:59:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-01 21:51:04                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-01 21:51:19                                  EventLog                        6008: The previous system shutdown at 9:29:57 PM on 2/1/2008 was unexpected.  
    System       Information     None       2008-02-01 21:51:19                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-01 21:51:19                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-01 21:51:19                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-01 21:51:29                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-01 21:51:30                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-01 21:51:33                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-01 21:51:34                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-01 21:51:35                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-01 21:51:35                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-01 21:51:52                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-01 22:09:02                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-01 22:09:02                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-01 23:21:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-01 23:21:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-01 23:49:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-01 23:49:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 01:04:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 01:04:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-02 02:26:10                                  DCOM                            10010: The server {E579AB5F-1CC4-44B4-BED9-DE0991FF0623} did not register with DCOM within the required timeout.  
    System       Information     None       2008-02-02 02:37:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 02:37:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 04:39:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 04:39:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 05:45:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 05:45:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 07:38:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 07:38:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 08:49:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 08:49:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 10:20:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 10:20:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 12:00:02                                  EventLog                        6013: The system uptime is 50957 seconds.  
    System       Information     None       2008-02-02 12:12:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 12:12:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 13:21:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 13:21:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 15:06:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 15:06:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 16:19:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 16:19:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 18:07:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 18:07:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 19:43:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 19:43:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-02 21:27:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 21:27:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Warning         None       2008-02-02 21:51:52                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-02-02 22:44:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-02 22:44:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 00:08:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 00:08:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 01:13:56                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 01:13:56                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 03:04:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 03:04:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 04:42:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 04:42:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 06:35:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 06:35:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 08:04:37                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 08:04:37                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 08:24:59                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 08:24:59                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 08:28:01                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 08:28:01                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 09:55:16                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 09:55:16                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 10:58:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 10:58:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 12:00:00                                  EventLog                        6013: The system uptime is 137355 seconds.  
    System       Information     None       2008-02-03 12:10:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 12:10:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 13:00:52                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 13:00:52                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-03 13:33:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 13:33:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 14:52:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 14:52:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 15:37:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 15:37:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 16:46:01                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 16:46:01                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 17:56:17                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 17:56:17                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 19:38:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 19:38:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 20:59:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 20:59:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 22:15:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 22:15:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-03 23:25:17                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-03 23:25:17                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-03 23:31:07                                  DCOM                            10010: The server {E579AB5F-1CC4-44B4-BED9-DE0991FF0623} did not register with DCOM within the required timeout.  
    System       Error           None       2008-02-04 00:01:01                                  VolSnap                         9: The flush and hold writes operation on volume C:\fs\F timed out while waiting for file system cleanup.  
    System       Information     None       2008-02-04 00:36:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 00:36:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 02:05:52                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 02:05:52                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 03:49:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 03:49:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 05:17:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 05:17:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 05:59:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 05:59:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 07:56:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 07:56:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 08:58:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 08:58:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 10:16:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 10:16:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 11:18:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 11:18:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 11:39:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 11:39:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 12:00:00                                  EventLog                        6013: The system uptime is 223755 seconds.  
    System       Information     None       2008-02-04 12:29:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 12:29:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 13:36:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 13:36:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 14:53:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 14:53:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 16:30:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 16:30:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 18:29:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 18:29:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 20:14:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 20:14:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 21:15:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 21:15:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-04 22:16:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-04 22:16:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-06 09:32:44                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-06 09:33:01                                  EventLog                        6008: The previous system shutdown at 10:38:23 PM on 2/4/2008 was unexpected.  
    System       Information     None       2008-02-06 09:33:01                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-06 09:33:01                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-06 09:33:01                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-06 09:33:11                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-06 09:33:12                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-06 09:33:15                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-06 09:33:17                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-06 09:33:17                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-06 09:33:18                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-06 09:33:37                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-06 09:50:47                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 09:50:47                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-06 11:39:47                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 11:39:47                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-06 12:00:05                                  EventLog                        6013: The system uptime is 8856 seconds.  
    System       Information     None       2008-02-06 13:28:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 13:28:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-06 18:17:23                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-06 18:17:37                                  EventLog                        6008: The previous system shutdown at 3:18:07 PM on 2/6/2008 was unexpected.  
    System       Information     None       2008-02-06 18:17:37                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-06 18:17:37                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-06 18:17:37                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-06 18:17:47                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-06 18:17:48                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-06 18:17:51                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-06 18:17:52                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-06 18:17:53                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-06 18:17:54                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-06 18:18:08                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-06 18:35:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 18:35:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-06 18:55:45                                  VolSnap                         25: The shadow copies of volume D: were deleted because the shadow copy storage could not grow in time.  Consider reducing the IO load on the system or choose a shadow copy storage volume that is not being shadow copied.  
    System       Information     None       2008-02-06 20:11:15                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-06 20:11:32                                  EventLog                        6008: The previous system shutdown at 7:52:38 PM on 2/6/2008 was unexpected.  
    System       Information     None       2008-02-06 20:11:32                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-06 20:11:32                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-06 20:11:32                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-06 20:11:42                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-06 20:11:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-06 20:11:46                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-06 20:11:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-06 20:11:47                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-06 20:11:48                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-06 20:18:40                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-06 20:18:54                                  EventLog                        6008: The previous system shutdown at 8:11:32 PM on 2/6/2008 was unexpected.  
    System       Information     None       2008-02-06 20:18:54                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-06 20:18:54                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-06 20:18:54                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-06 20:19:04                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-06 20:19:04                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-06 20:19:08                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-06 20:19:09                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-06 20:19:09                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-06 20:19:10                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-06 20:19:25                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-06 21:04:02                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-06 21:04:19                                  EventLog                        6008: The previous system shutdown at 8:27:54 PM on 2/6/2008 was unexpected.  
    System       Information     None       2008-02-06 21:04:19                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-06 21:04:19                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-06 21:04:19                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-06 21:04:29                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-06 21:04:29                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-06 21:04:33                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-06 21:04:34                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-06 21:04:34                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-06 21:04:35                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-06 21:04:49                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-06 21:21:57                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 21:21:57                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-06 22:59:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-06 22:59:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-07 00:40:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-07 00:40:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-07 18:12:29                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-07 18:12:45                                  EventLog                        6008: The previous system shutdown at 1:14:20 AM on 2/7/2008 was unexpected.  
    System       Information     None       2008-02-07 18:12:45                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-07 18:12:45                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-07 18:12:45                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-07 18:12:54                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-07 18:12:55                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-07 18:12:59                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-07 18:13:00                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-07 18:13:00                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-07 18:13:01                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-07 18:13:15                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-07 18:30:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-07 18:30:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-07 19:38:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-07 19:38:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-07 21:35:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-07 21:35:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-07 22:40:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-07 22:40:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-08 00:01:01                                  VolSnap                         9: The flush and hold writes operation on volume C:\fs\F timed out while waiting for file system cleanup.  
    System       Information     None       2008-02-08 00:12:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 00:12:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 00:33:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 00:33:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-08 00:41:34                                  DCOM                            10010: The server {E579AB5F-1CC4-44B4-BED9-DE0991FF0623} did not register with DCOM within the required timeout.  
    System       Information     None       2008-02-08 02:22:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 02:22:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 04:13:52                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 04:13:52                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 05:23:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 05:23:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 06:50:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 06:50:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 08:36:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 08:36:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 09:38:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 09:38:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 11:36:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 11:36:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 12:00:01                                  EventLog                        6013: The system uptime is 64062 seconds.  
    System       Information     None       2008-02-08 12:49:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 12:49:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 14:01:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 14:01:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 15:44:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 15:44:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-08 17:00:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-08 17:00:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 12:01:25                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-09 12:01:41                                  EventLog                        6008: The previous system shutdown at 5:02:48 PM on 2/8/2008 was unexpected.  
    System       Information     None       2008-02-09 12:01:41                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-09 12:01:41                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-09 12:01:41                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-09 12:01:50                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-09 12:01:51                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-09 12:01:55                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-09 12:01:55                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-09 12:01:55                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-09 12:01:56                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-09 12:02:13                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-09 12:20:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 12:20:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 13:11:04                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-09 13:11:20                                  EventLog                        6008: The previous system shutdown at 1:08:44 PM on 2/9/2008 was unexpected.  
    System       Information     None       2008-02-09 13:11:20                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-09 13:11:20                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-09 13:11:20                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-09 13:11:29                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-09 13:11:30                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-09 13:11:34                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-09 13:11:34                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-09 13:11:34                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-09 13:11:36                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-09 13:11:50                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-09 13:29:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 13:29:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 14:35:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 14:35:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 16:23:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 16:23:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 17:29:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 17:29:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 18:01:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 18:01:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 18:54:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 18:54:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 19:59:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 19:59:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 21:53:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 21:53:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-09 23:25:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-09 23:25:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 00:38:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 00:38:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 01:39:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 01:39:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 03:22:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 03:22:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 05:02:02                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 05:02:02                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 06:17:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 06:17:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 10:31:05                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-10 10:31:21                                  EventLog                        6008: The previous system shutdown at 7:44:22 AM on 2/10/2008 was unexpected.  
    System       Information     None       2008-02-10 10:31:21                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-10 10:31:21                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-10 10:31:21                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-10 10:31:30                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-10 10:31:31                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-10 10:31:34                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-10 10:31:35                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-10 10:31:36                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 10:31:36                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-10 10:31:51                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 10:49:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 10:49:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 12:00:00                                  EventLog                        6013: The system uptime is 5350 seconds.  
    System       Information     None       2008-02-10 12:18:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 12:18:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 13:23:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 13:23:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 15:17:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 15:17:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 16:30:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 16:30:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 17:03:14                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-10 17:03:30                                  EventLog                        6008: The previous system shutdown at 4:43:23 PM on 2/10/2008 was unexpected.  
    System       Information     None       2008-02-10 17:03:30                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-10 17:03:30                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-10 17:03:30                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-10 17:03:40                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-10 17:03:41                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-10 17:03:45                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-10 17:03:45                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 17:03:45                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-10 17:03:47                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-10 17:04:01                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 17:21:22                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 17:21:22                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 18:41:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 18:41:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 18:53:16                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-10 18:53:32                                  EventLog                        6008: The previous system shutdown at 6:41:32 PM on 2/10/2008 was unexpected.  
    System       Information     None       2008-02-10 18:53:32                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-10 18:53:32                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-10 18:53:32                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-10 18:53:42                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-10 18:53:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-10 18:53:46                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-10 18:53:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-10 18:53:47                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 18:53:48                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-10 18:54:02                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-10 19:11:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 19:11:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 20:27:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 20:27:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 22:05:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 22:05:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-10 23:35:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-10 23:35:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 00:57:41                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 00:57:41                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 02:29:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 02:29:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 03:49:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 03:49:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 04:47:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 04:47:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 06:22:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 06:22:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 07:23:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 07:23:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 09:21:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 09:21:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 10:27:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 10:27:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-11 11:02:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-11 11:02:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 08:32:47                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-12 08:33:01                                  EventLog                        6008: The previous system shutdown at 12:01:34 PM on 2/11/2008 was unexpected.  
    System       Information     None       2008-02-12 08:33:01                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-12 08:33:01                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-12 08:33:01                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-12 08:33:11                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-12 08:33:11                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-12 08:33:15                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-12 08:33:15                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-12 08:33:16                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-12 08:33:17                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-12 08:33:33                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-12 08:50:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 08:50:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 10:47:16                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 10:47:16                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 12:00:03                                  EventLog                        6013: The system uptime is 12450 seconds.  
    System       Information     None       2008-02-12 12:26:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 12:26:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 13:39:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 13:39:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 14:40:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 14:40:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 16:31:16                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 16:31:16                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 18:01:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 18:01:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-12 19:40:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-12 19:40:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-13 18:15:20                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-13 18:15:36                                  EventLog                        6008: The previous system shutdown at 8:27:05 PM on 2/12/2008 was unexpected.  
    System       Information     None       2008-02-13 18:15:36                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-13 18:15:36                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-13 18:15:36                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-13 18:15:46                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-13 18:15:47                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-13 18:15:50                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-13 18:15:51                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-13 18:15:51                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-13 18:15:52                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-13 18:16:09                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     8          2008-02-13 18:20:59                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB943055)  
    System       Information     8          2008-02-13 18:21:14                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942830)  
    System       Information     8          2008-02-13 18:21:19                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942830)  
    System       Information     8          2008-02-13 18:22:03                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830)  
    System       Information     8          2008-02-13 18:22:47                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830)  
    System       Information     8          2008-02-13 18:23:07                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     None       2008-02-13 18:33:00                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-02-13 18:34:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-13 18:34:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-13 18:35:10                                  BROWSER                         8033: The browser has forced an election on network \Device\NetBT_Tcpip_{AE308F59-993D-4CFE-BF1B-7E1048FECD3C} because a master browser was stopped.  
    System       Information     None       2008-02-13 20:15:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-13 20:15:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-14 18:17:58                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-14 18:18:13                                  EventLog                        6008: The previous system shutdown at 9:10:44 PM on 2/13/2008 was unexpected.  
    System       Information     None       2008-02-14 18:18:13                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-14 18:18:13                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-14 18:18:13                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-14 18:18:23                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-14 18:18:24                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-14 18:18:24                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-14 18:18:28                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-14 18:18:28                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-14 18:18:29                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-14 18:18:44                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     8          2008-02-14 18:20:04                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     8          2008-02-14 18:21:48                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     None       2008-02-14 18:36:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-14 18:36:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-14 20:02:42                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-14 20:02:42                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-14 21:30:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-14 21:30:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-14 22:28:21                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-14 22:28:32                                  EventLog                        6008: The previous system shutdown at 9:53:15 PM on 2/14/2008 was unexpected.  
    System       Information     None       2008-02-14 22:28:32                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-14 22:28:32                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-14 22:28:32                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-14 22:28:41                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-14 22:28:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-14 22:28:45                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-14 22:28:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-14 22:28:47                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-14 22:28:48                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-14 22:29:02                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-14 22:46:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-14 22:46:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Error           None       2008-02-15 00:01:05                                  VolSnap                         9: The flush and hold writes operation on volume C:\fs\F timed out while waiting for file system cleanup.  
    System       Information     None       2008-02-15 00:19:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 00:19:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 01:52:56                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 01:52:56                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 02:55:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 02:55:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 04:53:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 04:53:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 06:03:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 06:03:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 07:17:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 07:17:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 08:21:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 08:21:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 09:54:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 09:54:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 11:01:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 11:01:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 12:00:02                                  EventLog                        6013: The system uptime is 48725 seconds.  
    System       Information     None       2008-02-15 12:08:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 12:08:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     8          2008-02-15 12:36:38                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     None       2008-02-15 12:52:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 12:52:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-15 14:37:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-15 14:37:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 02:22:10                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-16 02:22:19                                  EventLog                        6008: The previous system shutdown at 3:59:34 PM on 2/15/2008 was unexpected.  
    System       Information     None       2008-02-16 02:22:19                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-16 02:22:19                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-16 02:22:19                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-16 02:22:28                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-16 02:22:29                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-16 02:22:32                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-16 02:22:33                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-16 02:22:33                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-16 02:22:34                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-16 02:22:51                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-16 02:40:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 02:40:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 04:32:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 04:32:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 06:12:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 06:12:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 09:07:48                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-16 09:07:59                                  EventLog                        6008: The previous system shutdown at 7:35:22 AM on 2/16/2008 was unexpected.  
    System       Information     None       2008-02-16 09:07:59                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-16 09:07:59                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-16 09:07:59                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-16 09:08:08                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-16 09:08:09                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-16 09:08:13                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-16 09:08:13                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-16 09:08:13                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-16 09:08:14                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-16 09:08:29                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     8          2008-02-16 09:11:43                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Windows Malicious Software Removal Tool - February 2008 (KB890830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     None       2008-02-16 09:25:57                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 09:25:57                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 11:02:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 11:02:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 11:11:46  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB946026 was installed.  
    System       Information     8          2008-02-16 11:11:52                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB946026)  
    System       Information     None       2008-02-16 11:11:54  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB943055 was installed.  
    System       Information     8          2008-02-16 11:12:05                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB943055)  
    System       Information     None       2008-02-16 11:12:10  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB942831 was installed.  
    System       Information     8          2008-02-16 11:12:15                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB942831)  
    System       Information     None       2008-02-16 11:12:18  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB942830 was installed.  
    System       Information     8          2008-02-16 11:12:24                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Security Update for Windows Server 2003 (KB942830)  
    System       Information     None       2008-02-16 11:12:33  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB944533 was installed.  
    System       Information     8          2008-02-16 11:12:41                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     8          2008-02-16 11:12:41                                  Windows Update Agent            21: Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates:  - Security Update for Windows Server 2003 (KB946026) - Security Update for Windows Server 2003 (KB943055) - Security Update for Windows Server 2003 (KB942831) - Security Update for Windows Server 2003 (KB942830) - Cumulative Security Update for Internet Explorer 6 for Windows Server 2003 (KB944533)  
    System       Information     None       2008-02-16 11:13:59                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-02-16 11:14:51                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-02-16 11:15:02                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-16 11:15:02                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-16 11:15:03                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-16 11:15:12                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-16 11:15:13                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-16 11:15:16                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-16 11:15:17                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-16 11:15:19                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-16 11:34:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 11:34:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 12:00:00                                  EventLog                        6013: The system uptime is 2728 seconds.  
    System       Information     None       2008-02-16 13:14:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 13:14:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 15:07:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 15:07:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 16:01:32                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-16 16:01:42                                  EventLog                        6008: The previous system shutdown at 3:57:03 PM on 2/16/2008 was unexpected.  
    System       Information     None       2008-02-16 16:01:42                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-16 16:01:42                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-16 16:01:42                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-16 16:01:52                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-16 16:01:52                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-16 16:01:56                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-16 16:01:57                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-16 16:01:58                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-16 16:19:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 16:19:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 17:32:49                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 17:32:49                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 19:00:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 19:00:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 20:00:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 20:00:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 21:12:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 21:12:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-16 22:46:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-16 22:46:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 00:23:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 00:23:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 02:08:22                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 02:08:22                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 04:04:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 04:04:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 05:07:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 05:07:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 06:30:56                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 06:30:56                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 08:09:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 08:09:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 09:29:41                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 09:29:41                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 10:30:56                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 10:30:56                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 11:39:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 11:39:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 12:00:01                                  EventLog                        6013: The system uptime is 71934 seconds.  
    System       Information     None       2008-02-17 12:10:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 12:10:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 13:31:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 13:31:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 15:13:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 15:13:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 15:34:04                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-17 15:34:05                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Warning         None       2008-02-17 16:01:57                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-02-17 16:20:00                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 16:20:00                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 16:58:28                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-17 16:58:42                                  EventLog                        6008: The previous system shutdown at 4:42:43 PM on 2/17/2008 was unexpected.  
    System       Information     None       2008-02-17 16:58:42                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-17 16:58:42                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-17 16:58:42                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-17 16:58:51                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-17 16:58:52                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-17 16:58:55                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-17 16:58:56                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-17 16:58:58                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-17 17:16:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 17:16:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 18:20:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 18:20:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 19:22:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 19:22:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 21:15:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 21:15:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-17 23:13:41                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-17 23:13:41                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-18 18:30:43                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-18 18:30:58                                  EventLog                        6008: The previous system shutdown at 12:07:42 AM on 2/18/2008 was unexpected.  
    System       Information     None       2008-02-18 18:30:58                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-18 18:30:58                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-18 18:30:59                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-18 18:31:08                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-18 18:31:09                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-18 18:31:13                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-18 18:31:13                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-18 18:31:15                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-18 18:48:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-18 18:48:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-18 20:36:48                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-18 20:37:03                                  EventLog                        6008: The previous system shutdown at 8:11:03 PM on 2/18/2008 was unexpected.  
    System       Information     None       2008-02-18 20:37:03                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-18 20:37:03                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-18 20:37:03                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-18 20:37:12                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-18 20:37:13                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-18 20:37:16                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-18 20:37:17                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-18 20:37:18                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-18 20:54:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-18 20:54:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-18 22:00:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-18 22:00:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-18 23:51:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-18 23:51:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-19 00:30:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-19 00:30:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-19 01:09:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-19 01:09:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-19 08:37:10                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-19 08:37:23                                  EventLog                        6008: The previous system shutdown at 2:20:03 AM on 2/19/2008 was unexpected.  
    System       Information     None       2008-02-19 08:37:23                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-19 08:37:23                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-19 08:37:23                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-19 08:37:33                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-19 08:37:33                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-19 08:37:37                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-19 08:37:37                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-19 08:37:39                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-19 08:55:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-19 08:55:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 09:49:45                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-20 09:50:00                                  EventLog                        6008: The previous system shutdown at 10:15:24 AM on 2/19/2008 was unexpected.  
    System       Information     None       2008-02-20 09:50:00                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-20 09:50:00                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-20 09:50:00                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-20 09:50:10                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-20 09:50:11                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-20 09:50:14                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-20 09:50:15                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-20 09:50:16                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-20 10:07:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 10:07:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 11:28:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 11:28:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 12:00:00                                  EventLog                        6013: The system uptime is 7833 seconds.  
    System       Information     None       2008-02-20 13:08:47                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 13:08:47                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 14:23:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 14:23:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 15:49:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 15:49:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 16:09:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 16:09:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 18:03:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 18:03:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 19:38:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 19:38:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 20:47:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 20:47:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-20 22:38:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-20 22:38:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-21 00:33:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-21 00:33:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-21 02:04:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-21 02:04:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-21 03:42:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-21 03:42:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-21 04:34:49                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-21 04:34:49                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 00:29:33                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-22 00:29:48                                  EventLog                        6008: The previous system shutdown at 5:32:01 AM on 2/21/2008 was unexpected.  
    System       Information     None       2008-02-22 00:29:48                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-22 00:29:48                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-22 00:29:49                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-22 00:29:57                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-22 00:29:58                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-22 00:30:02                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-22 00:30:02                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-22 00:30:04                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-22 00:47:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 00:47:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 01:48:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 01:48:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 02:56:01                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 02:56:01                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 04:28:17                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 04:28:17                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 08:25:29                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-22 08:25:43                                  EventLog                        6008: The previous system shutdown at 4:34:49 AM on 2/22/2008 was unexpected.  
    System       Information     None       2008-02-22 08:25:43                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-22 08:25:43                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-22 08:25:43                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-22 08:25:53                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-22 08:25:54                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-22 08:25:57                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-22 08:25:57                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-22 08:25:58                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-22 08:43:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 08:43:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 09:49:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 09:49:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 11:37:56                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 11:37:56                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 12:00:00                                  EventLog                        6013: The system uptime is 12890 seconds.  
    System       Information     None       2008-02-22 13:08:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 13:08:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 14:08:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 14:08:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 16:01:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 16:01:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 17:43:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 17:43:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 19:25:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 19:25:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 20:34:26                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 20:34:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 21:44:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 21:44:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 22:52:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 22:52:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-22 23:58:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-22 23:58:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 11:05:48                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-23 11:06:02                                  EventLog                        6008: The previous system shutdown at 12:10:44 AM on 2/23/2008 was unexpected.  
    System       Information     None       2008-02-23 11:06:02                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-23 11:06:02                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-23 11:06:02                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-23 11:06:11                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-23 11:06:12                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-23 11:06:15                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-23 11:06:16                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-23 11:06:17                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-23 11:06:17                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-23 11:06:38                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-23 11:23:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 11:23:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 12:00:06                                  EventLog                        6013: The system uptime is 3272 seconds.  
    System       Information     None       2008-02-23 13:12:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 13:12:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 14:48:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 14:48:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 16:16:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 16:16:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 17:25:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 17:25:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 19:12:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 19:12:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 21:02:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 21:02:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 22:17:04                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 22:17:04                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-23 23:19:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-23 23:19:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 00:28:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 00:28:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 02:11:49                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 02:11:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 03:38:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 03:38:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 13:29:05                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-24 13:29:20                                  EventLog                        6008: The previous system shutdown at 4:49:13 AM on 2/24/2008 was unexpected.  
    System       Information     None       2008-02-24 13:29:20                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-24 13:29:20                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-24 13:29:20                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-24 13:29:30                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-24 13:29:32                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-24 13:29:35                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-24 13:29:36                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-24 13:29:37                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-24 13:29:37                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-24 13:29:52                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-24 13:47:03                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 13:47:03                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 15:39:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 15:39:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 17:24:22                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 17:24:22                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 17:52:03                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-24 17:52:18                                  EventLog                        6008: The previous system shutdown at 5:45:23 PM on 2/24/2008 was unexpected.  
    System       Information     None       2008-02-24 17:52:18                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-24 17:52:18                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-24 17:52:18                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-24 17:52:27                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-24 17:52:28                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-24 17:52:32                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-24 17:52:32                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-24 17:52:33                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-24 17:52:33                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-24 17:52:48                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-24 18:10:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 18:10:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 19:12:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 19:12:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 19:29:06                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 19:29:06                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 20:19:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 20:19:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 21:47:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 21:47:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-24 23:14:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-24 23:14:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-25 00:21:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-25 00:21:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-25 01:45:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-25 01:45:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-26 02:08:01                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-26 02:08:16                                  EventLog                        6008: The previous system shutdown at 2:27:20 AM on 2/25/2008 was unexpected.  
    System       Information     None       2008-02-26 02:08:16                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-26 02:08:16                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-26 02:08:16                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-26 02:08:26                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-26 02:08:27                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-26 02:08:30                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-26 02:08:31                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-26 02:08:32                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Error           None       2008-02-26 02:08:44                                  W32Time                         17: Time Provider NtpClient: An error occurred during DNS lookup of the manually  configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15  minutes.  The error was: A socket operation was attempted to an unreachable host. (0x80072751)  
    System       Information     None       2008-02-26 02:23:44                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-26 02:23:47                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-02-26 02:26:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-26 02:26:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-26 22:13:30                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-26 22:13:44                                  EventLog                        6008: The previous system shutdown at 3:49:19 AM on 2/26/2008 was unexpected.  
    System       Information     None       2008-02-26 22:13:44                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-26 22:13:44                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-26 22:13:44                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-26 22:13:54                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-26 22:13:55                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-26 22:13:58                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-26 22:13:59                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-26 22:14:00                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-26 22:14:00                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-26 22:14:15                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-26 22:31:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-26 22:31:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-26 23:59:47                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-26 23:59:47                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 01:34:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 01:34:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 03:19:25                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-27 03:19:25                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-27 03:22:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 03:22:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 05:06:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 05:06:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 05:39:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 05:39:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 06:57:00                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 06:57:00                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 08:25:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 08:25:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 09:28:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 09:28:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 10:44:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 10:44:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 18:00:29                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-27 18:00:44                                  EventLog                        6008: The previous system shutdown at 10:51:46 AM on 2/27/2008 was unexpected.  
    System       Information     None       2008-02-27 18:00:44                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-27 18:00:44                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-27 18:00:44                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-27 18:00:53                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-27 18:00:55                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-27 18:00:58                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-27 18:00:59                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-27 18:00:59                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 18:01:00                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-27 18:01:14                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 18:18:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 18:18:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 18:56:09                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-27 18:56:24                                  EventLog                        6008: The previous system shutdown at 6:32:46 PM on 2/27/2008 was unexpected.  
    System       Information     None       2008-02-27 18:56:24                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-27 18:56:24                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-27 18:56:24                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-27 18:56:33                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-27 18:56:35                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-27 18:56:39                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-27 18:56:39                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-27 18:56:39                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 18:56:41                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-27 18:56:57                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 19:14:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 19:14:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 20:28:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 20:28:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 21:07:14                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-27 21:07:27                                  EventLog                        6008: The previous system shutdown at 8:43:26 PM on 2/27/2008 was unexpected.  
    System       Information     None       2008-02-27 21:07:27                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-27 21:07:27                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-27 21:07:28                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-27 21:07:37                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-27 21:07:39                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-27 21:07:42                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-27 21:07:42                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-27 21:07:43                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 21:07:43                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-27 21:07:58                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-02-27 21:25:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 21:25:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-27 22:30:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-27 22:30:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-28 00:00:01  Administrator                   USER32                          1074: The process winlogon.exe has initiated the power off of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: power off    Comment:   
    System       Information     None       2008-02-28 00:00:04                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-02-28 18:49:43                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-02-28 18:49:55                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-28 18:49:55                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-28 18:49:55                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-28 18:50:05                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-28 18:50:06                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-28 18:50:09                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-28 18:50:10                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-28 18:50:11                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-28 19:07:47                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-28 19:07:47                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-28 21:06:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-28 21:06:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-28 22:55:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-28 22:55:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 00:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-02-29 00:00:04                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-02-29 00:01:18                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-02-29 00:01:31                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-29 00:01:31                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-29 00:01:31                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-29 00:01:41                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-29 00:01:43                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-29 00:01:46                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-29 00:01:47                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-29 00:01:52                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-29 00:19:24                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 00:19:24                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 00:49:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 00:49:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 01:38:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 01:38:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 03:25:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 03:25:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 04:45:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 04:45:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 05:47:10                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-29 05:47:11                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-29 06:35:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 06:35:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 08:03:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 08:03:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 09:47:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 09:47:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 11:37:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 11:37:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 12:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-02-29 12:00:01                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-02-29 12:01:15                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-02-29 12:01:28                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-29 12:01:28                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-29 12:01:28                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-29 12:01:38                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-29 12:01:40                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-29 12:01:43                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-29 12:01:44                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-29 12:01:49                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-29 12:19:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 12:19:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 14:03:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 14:03:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 14:49:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 14:49:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 16:45:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 16:45:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 18:11:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 18:11:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 19:15:37                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-29 19:15:51                                  EventLog                        6008: The previous system shutdown at 7:14:30 PM on 2/29/2008 was unexpected.  
    System       Information     None       2008-02-29 19:15:51                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-29 19:15:51                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-29 19:15:51                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-29 19:16:01                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-29 19:16:02                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-29 19:16:06                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-29 19:16:06                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-29 19:16:08                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-29 19:33:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 19:33:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 20:03:09                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-02-29 20:03:24                                  EventLog                        6008: The previous system shutdown at 7:59:53 PM on 2/29/2008 was unexpected.  
    System       Information     None       2008-02-29 20:03:24                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-02-29 20:03:24                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-02-29 20:03:24                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-02-29 20:03:34                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-02-29 20:03:35                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-02-29 20:03:38                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-02-29 20:03:39                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-02-29 20:03:40                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-02-29 20:28:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 20:28:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 20:33:42                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-29 20:33:43                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-02-29 21:30:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 21:30:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-02-29 22:46:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-02-29 22:46:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 09:02:34                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-01 09:02:49                                  EventLog                        6008: The previous system shutdown at 10:58:25 PM on 2/29/2008 was unexpected.  
    System       Information     None       2008-03-01 09:02:49                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-01 09:02:49                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-01 09:02:49                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-01 09:02:59                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-01 09:03:01                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-01 09:03:04                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-01 09:03:05                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-01 09:03:06                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-01 09:20:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 09:20:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 10:27:57                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 10:27:57                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 10:49:23                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 10:49:23                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 12:00:00                                  EventLog                        6013: The system uptime is 10667 seconds.  
    System       Information     None       2008-03-01 12:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-03-01 12:00:01                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-01 12:01:17                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-01 12:01:30                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-01 12:01:30                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-01 12:01:30                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-01 12:01:39                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-01 12:01:41                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-01 12:01:44                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-01 12:01:45                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-01 12:01:46                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-01 12:19:22                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 12:19:22                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 13:46:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 13:46:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 14:56:54                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 14:56:54                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 16:29:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 16:29:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 17:43:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 17:43:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 18:49:50                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 18:49:50                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 20:39:07                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 20:39:07                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-01 22:28:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-01 22:28:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 10:02:09                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-09 10:02:27                                  EventLog                        6008: The previous system shutdown at 10:48:33 PM on 3/1/2008 was unexpected.  
    System       Information     None       2008-03-09 10:02:27                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-09 10:02:27                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-09 10:02:27                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-09 10:02:37                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-09 10:02:39                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-09 10:02:42                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-09 10:02:43                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-09 10:02:44                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-09 10:02:44                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-09 10:03:10                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-09 10:20:33                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 10:20:33                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 11:35:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 11:35:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 11:49:57                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-09 12:14:00                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-09 12:14:13                                  EventLog                        6008: The previous system shutdown at 11:53:39 AM on 3/9/2008 was unexpected.  
    System       Information     None       2008-03-09 12:14:13                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-09 12:14:13                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-09 12:14:13                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-09 12:14:22                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-09 12:14:24                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-09 12:14:28                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-09 12:14:28                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-09 12:14:28                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-09 12:14:29                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-09 12:14:44                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-09 12:32:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 12:32:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 13:37:19                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 13:37:19                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 15:22:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 15:22:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 16:02:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 16:02:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 16:29:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 16:29:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 18:07:15                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 18:07:15                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-09 19:46:32                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-09 19:46:32                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 00:11:39                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-12 00:11:54                                  EventLog                        6008: The previous system shutdown at 8:06:14 PM on 3/9/2008 was unexpected.  
    System       Information     None       2008-03-12 00:11:54                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-12 00:11:54                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-12 00:11:54                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-12 00:12:03                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-12 00:12:05                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-12 00:12:09                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-12 00:12:09                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-12 00:12:10                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-12 00:12:10                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-12 00:12:27                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     8          2008-03-12 00:19:48                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830)  
    System       Information     8          2008-03-12 00:19:55                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830) - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-12 00:34:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 00:34:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 02:21:19                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 02:21:19                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 03:48:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 03:48:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 05:15:55                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 05:15:55                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 06:14:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 06:14:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 06:53:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 06:53:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 08:41:30                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 08:41:30                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 09:53:48                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 09:53:48                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 11:24:02                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 11:24:02                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 12:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-03-12 12:00:01                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-12 12:01:14                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-12 12:01:28                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-12 12:01:28                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-12 12:01:28                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-12 12:01:37                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-12 12:01:39                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-12 12:01:42                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-12 12:01:43                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-12 12:01:44                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-12 12:19:19                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 12:19:19                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 13:24:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 13:24:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 14:37:52                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 14:37:52                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 16:33:12                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 16:33:12                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 18:09:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 18:09:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 19:32:44                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 19:32:44                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 20:50:05                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 20:50:05                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     8          2008-03-12 20:52:54                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830) - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-12 21:08:22                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 21:08:22                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 22:44:09                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 22:44:09                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-12 23:51:29                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-12 23:51:29                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 00:00:03  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-03-13 00:00:10                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-13 00:01:29                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-13 00:01:43                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-13 00:01:43                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-13 00:01:43                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-13 00:01:52                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-13 00:01:53                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-13 00:01:57                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-13 00:01:58                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-13 00:01:59                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-13 00:19:37                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 00:19:37                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 18:22:59                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-13 18:23:14                                  EventLog                        6008: The previous system shutdown at 1:03:45 AM on 3/13/2008 was unexpected.  
    System       Information     None       2008-03-13 18:23:14                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-13 18:23:14                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-13 18:23:14                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-13 18:23:24                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-13 18:23:26                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-13 18:23:29                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-13 18:23:29                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-13 18:23:31                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     8          2008-03-13 18:27:41                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830) - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-13 18:42:35                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 18:42:35                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 20:09:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 20:09:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 20:24:21                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-13 20:24:37                                  EventLog                        6008: The previous system shutdown at 8:19:16 PM on 3/13/2008 was unexpected.  
    System       Information     None       2008-03-13 20:24:37                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-13 20:24:37                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-13 20:24:37                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-13 20:24:46                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-13 20:24:48                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-13 20:24:51                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-13 20:24:52                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-13 20:24:53                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-13 20:42:28                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 20:42:28                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 22:03:42                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 22:03:42                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-13 23:09:59                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-13 23:09:59                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 00:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-03-14 00:00:03                                  EventLog                        6006: The Event log service was stopped.  
    System       Warning         None       2008-03-14 00:00:59                                  VolSnap                         30: An unfinished create of a shadow copy of volume D: was deleted.  
    System       Warning         None       2008-03-14 00:01:07                                  VolSnap                         30: An unfinished create of a shadow copy of volume \\?\Volume{d3fa1534-c39c-11dc-bb07-001d602d2664} was deleted.  
    System       Information     None       2008-03-14 00:01:17                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-14 00:01:31                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-14 00:01:31                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-14 00:01:31                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-14 00:01:40                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-14 00:01:42                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-14 00:01:45                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-14 00:01:46                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-14 00:01:47                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     8          2008-03-14 00:13:24                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830) - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-14 00:22:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 00:22:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 01:43:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 01:43:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 03:29:57                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 03:29:57                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 04:41:18                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 04:41:18                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 17:45:33                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-14 17:45:48                                  EventLog                        6008: The previous system shutdown at 5:16:32 AM on 3/14/2008 was unexpected.  
    System       Information     None       2008-03-14 17:45:48                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-14 17:45:48                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-14 17:45:48                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-14 17:45:57                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-14 17:45:59                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-14 17:46:03                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-14 17:46:03                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-14 17:46:04                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     8          2008-03-14 17:49:23                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Windows Malicious Software Removal Tool - March 2008 (KB890830) - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-14 18:03:39                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 18:03:39                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 18:07:08                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-14 18:07:08                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-14 18:23:19  Administrator                   NtServicePack                   4377: Windows Server 2003 Hotfix KB948496 was installed.  
    System       Information     8          2008-03-14 18:23:25                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Server 2003 (KB948496)  
    System       Information     8          2008-03-14 18:23:25                                  Windows Update Agent            21: Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates:  - Update for Windows Server 2003 (KB948496)  
    System       Information     None       2008-03-14 18:24:07                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-14 18:25:05                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-14 18:25:19                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-14 18:25:19                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-14 18:25:19                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-14 18:25:28                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-14 18:25:30                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-14 18:25:34                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-14 18:25:34                                  WMConnectCDS                    14202: Service 'WMConnectCDS' started.  
    System       Information     None       2008-03-14 18:25:36                                  WMConnectCDS                    14204: Log file 'C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows Media Connect 2\FileScanLogFile.txt' is created for media files and shares scanning results.  
    System       Information     None       2008-03-14 18:32:37                                  WMConnectCDS                    14203: Service 'WMConnectCDS' stopped.  
    System       Information     None       2008-03-14 18:44:43                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 18:44:43                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 19:55:01                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 19:55:01                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 21:30:17                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 21:30:17                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 23:05:36                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 23:05:36                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-14 23:45:10                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-14 23:45:10                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 00:00:00  Administrator                   USER32                          1074: The process winlogon.exe has initiated the restart of computer WEBERSERVER on behalf of user WEBERSERVER\Administrator for the following reason: No title for this reason could be found    Reason Code: 0x840000ff    Shutdown Type: restart    Comment:   
    System       Information     None       2008-03-15 00:00:03                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-15 00:01:15                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-15 00:01:32                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-15 00:01:32                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-15 00:01:32                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-15 00:01:41                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-15 00:01:43                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-15 00:01:46                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-15 00:19:21                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 00:19:21                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 01:52:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 01:52:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 02:31:03                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 02:31:03                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 03:42:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 03:42:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 05:11:13                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 05:11:13                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 05:28:23                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 05:28:23                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 06:39:31                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 06:39:31                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 07:24:01                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 07:24:01                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 07:42:51                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 07:42:51                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 12:45:28                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-15 12:45:41                                  EventLog                        6008: The previous system shutdown at 8:08:32 AM on 3/15/2008 was unexpected.  
    System       Information     None       2008-03-15 12:45:41                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-15 12:45:41                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-15 12:45:42                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-15 12:45:51                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-15 12:45:53                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-15 12:45:56                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-15 13:03:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 13:03:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 15:05:39                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 15:05:40                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-15 15:37:38                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 15:37:38                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 18:43:17                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 18:43:17                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 20:39:46                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 20:39:46                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 21:58:20                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 21:58:20                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-15 23:41:40                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-15 23:41:40                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 01:36:58                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 01:36:58                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 02:19:53                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 02:19:53                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 03:01:14                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 03:01:14                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 03:04:52                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 03:04:52                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 04:59:34                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 04:59:34                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 05:28:03                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 05:28:19                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 06:23:52                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 06:23:52                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 08:09:11                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 08:09:11                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 09:14:27                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 09:14:27                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 10:06:50                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 10:06:50                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 10:22:45                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 10:22:45                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 10:28:53                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 10:28:53                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-16 11:28:08                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 11:28:08                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 12:00:00                                  EventLog                        6013: The system uptime is 83692 seconds.  
    System       Warning         None       2008-03-16 12:45:59                                  W32Time                         36: The time service has not synchronized the system time for 86400 seconds   because none of the time service providers provided a usable time   stamp. The time service is no longer synchronized and cannot provide   the time to other clients or update the system clock. Monitor the   system events displayed in the Event  Viewer to make sure that a more   serious problem does not exist.   
    System       Information     None       2008-03-16 13:18:25                                  WinHttpAutoProxySvc             12503: The WinHTTP Web Proxy Auto-Discovery Service has been idle for 15 minutes, it will be shut down.  
    System       Information     None       2008-03-16 13:18:25                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 13:36:13                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-16 13:36:23                                  EventLog                        6008: The previous system shutdown at 1:32:43 PM on 3/16/2008 was unexpected.  
    System       Information     None       2008-03-16 13:36:23                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-16 13:36:23                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-16 13:36:23                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-16 13:36:33                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-16 13:36:36                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-16 13:36:39                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-16 13:47:26                                  WinHttpAutoProxySvc             12517: The WinHTTP Web Proxy Auto-Discovery Service suspended operation.  
    System       Information     None       2008-03-16 15:39:05                                  Application Popup               26: Application popup: Windows : If you shut down this remote computer, no one can use it until someone at the remote location manually restarts it.    Do you want to continue shutting down?  
    System       Information     None       2008-03-16 15:39:19                                  EventLog                        6006: The Event log service was stopped.  
    System       Information     None       2008-03-16 15:43:22                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Information     None       2008-03-16 15:43:35                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-16 15:43:35                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-16 15:43:35                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-16 15:43:44                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-16 15:43:45                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-16 15:43:49                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-17 00:51:13                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-17 02:07:30                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-17 02:07:31                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     None       2008-03-18 18:30:20                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-18 18:30:37                                  EventLog                        6008: The previous system shutdown at 3:08:36 AM on 3/17/2008 was unexpected.  
    System       Information     None       2008-03-18 18:30:37                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-18 18:30:37                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-18 18:30:37                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-18 18:30:47                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-18 18:30:49                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-18 18:30:52                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-19 00:11:42                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-03-19 00:11:49                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.232.182:123).  
    System       Information     None       2008-03-19 23:32:59                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-19 23:33:16                                  EventLog                        6008: The previous system shutdown at 3:13:45 AM on 3/19/2008 was unexpected.  
    System       Information     None       2008-03-19 23:33:16                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-19 23:33:16                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-19 23:33:16                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-19 23:33:25                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-19 23:33:27                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-19 23:33:30                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-19 23:33:31                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-19 23:33:47                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-20 18:34:11                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-20 18:34:27                                  EventLog                        6008: The previous system shutdown at 12:08:17 AM on 3/20/2008 was unexpected.  
    System       Information     None       2008-03-20 18:34:27                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-20 18:34:27                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-20 18:34:27                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-20 18:34:37                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-20 18:34:39                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-20 18:34:42                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-20 18:34:43                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-20 18:35:01                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-21 12:00:03                                  EventLog                        6013: The system uptime is 62764 seconds.  
    System       Information     None       2008-03-21 17:41:24                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-21 17:41:41                                  EventLog                        6008: The previous system shutdown at 1:18:30 PM on 3/21/2008 was unexpected.  
    System       Information     None       2008-03-21 17:41:41                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-21 17:41:41                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-21 17:41:41                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-21 17:41:51                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-21 17:41:52                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-21 17:41:55                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-21 17:41:57                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-21 17:42:12                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-24 17:41:50                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-24 17:42:06                                  EventLog                        6008: The previous system shutdown at 5:41:41 PM on 3/21/2008 was unexpected.  
    System       Information     None       2008-03-24 17:42:06                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-24 17:42:06                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-24 17:42:06                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-24 17:42:16                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-24 17:42:17                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-24 17:42:21                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-24 17:42:22                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-24 17:42:41                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-26 09:34:19                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-26 09:34:33                                  EventLog                        6008: The previous system shutdown at 7:06:09 PM on 3/24/2008 was unexpected.  
    System       Information     None       2008-03-26 09:34:33                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-26 09:34:33                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-26 09:34:33                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-26 09:34:43                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-26 09:34:44                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-26 09:34:48                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-26 09:34:49                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-26 09:35:04                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     8          2008-03-26 10:23:53                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Update for Windows Home Server (KB946146)  
    System       Information     None       2008-03-26 12:00:01                                  EventLog                        6013: The system uptime is 8760 seconds.  
    System       Information     8          2008-03-26 17:43:39                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Update for Windows Home Server (KB946146)  
    System       Information     None       2008-03-26 21:36:41                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-26 21:36:54                                  EventLog                        6008: The previous system shutdown at 9:15:34 PM on 3/26/2008 was unexpected.  
    System       Information     None       2008-03-26 21:36:54                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-26 21:36:54                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-26 21:36:54                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-26 21:37:04                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-26 21:37:05                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-26 21:37:08                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-26 21:37:09                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-26 21:37:25                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-27 02:21:01                                  VolSnap                         33: The oldest shadow copy of volume D: was deleted to keep disk space usage for shadow copies of volume D: below the user defined limit.  
    System       Information     8          2008-03-27 06:04:00                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Update for Windows Home Server (KB946146)  
    System       Information     None       2008-03-27 12:00:02                                  EventLog                        6013: The system uptime is 51819 seconds.  
    System       Information     None       2008-03-28 17:43:03                                  IPSec                           4295: The IPSec Driver is starting in Bypass mode. No IPSec security is being applied  while this computer starts up. IPSec policies, if they have been assigned, will  be applied to this computer after the IPSec services start.  
    System       Error           None       2008-03-28 17:43:17                                  EventLog                        6008: The previous system shutdown at 8:46:56 PM on 3/27/2008 was unexpected.  
    System       Information     None       2008-03-28 17:43:17                                  EventLog                        6009: Microsoft (R) Windows (R) 5.02. 3790 Service Pack 2 Uniprocessor Free.  
    System       Information     None       2008-03-28 17:43:17                                  EventLog                        6005: The Event log service was started.  
    System       Information     None       2008-03-28 17:43:17                                  DCOM                            10026: The COM sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\Ole\EventLog.   
    System       Information     None       2008-03-28 17:43:27                                  AeLookupSvc                     3: The Application Experience Lookup service started successfully.  
    System       Information     None       2008-03-28 17:43:28                                  SBCore                          1000: The SBCore service started successfully.  
    System       Information     None       2008-03-28 17:43:31                                  Virtual Disk Service            3: Service started.  
    System       Information     None       2008-03-28 17:43:32                                  W32Time                         37: The time provider NtpClient is currently receiving valid time data from time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     None       2008-03-28 17:43:51                                  W32Time                         35: The time service is now synchronizing the system time with the time  source time.windows.com (ntp.m|0x1|192.168.0.11:123->207.46.197.32:123).  
    System       Information     8          2008-03-28 17:47:28                                  Windows Update Agent            17: Installation Ready: The following updates are downloaded and ready for installation. To install the updates, an administrator should log on to this computer and Windows will prompt with further instructions:  - Update for Windows Home Server (KB946146)  
    System       Information     None       2008-03-29 10:55:54  Administrator                   NtServicePack                   4377: Windows Home Server Hotfix KB946146 was installed.  
    System       Information     8          2008-03-29 10:56:00                                  Windows Update Agent            19: Installation Successful: Windows successfully installed the following update: Update for Windows Home Server (KB946146)  
    System       Information     8          2008-03-29 10:56:00                                  Windows Update Agent            21: Restart Required: To complete the installation of the following updates, the computer must be restarted. Until this computer has been restarted, Windows cannot search for or download new updates:  - Update for Windows Home Server (KB946146)  


--------[ Database Software ]-------------------------------------------------------------------------------------------

    Database Drivers:
      Borland Database Engine                           -
      Borland InterBase Client                          -
      Easysoft ODBC-InterBase 6                         -
      Easysoft ODBC-InterBase 7                         -
      Firebird Client                                   -
      Jet Engine                                        4.00.9505.0
      MDAC                                              2.82.3959.0 (srv03_sp2_rtm.070216-1710)
      ODBC                                              3.526.3959.0 (srv03_sp2_rtm.070216-1710)
      MySQL Connector/ODBC                              -
      Oracle Client                                     -
      PsqlODBC                                          -
      Sybase ASE ODBC                                   -

    Database Servers:
      Borland InterBase Server                          -
      Firebird Server                                   -
      Microsoft SQL Server                              -
      MySQL Server                                      -
      PostgreSQL Server                                 -
      Oracle Server                                     -
      Sybase SQL Server                                 -


--------[ ODBC Drivers ]------------------------------------------------------------------------------------------------

    Driver da Microsoft para arquivos texto (*.txt; *.csv)      odbcjt32.dll        4.0.6305.0            *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Driver do Microsoft Access (*.mdb)                          odbcjt32.dll        4.0.6305.0            *.mdb
    Driver do Microsoft dBase (*.dbf)                           odbcjt32.dll        4.0.6305.0            *.dbf,*.ndx,*.mdx
    Driver do Microsoft Excel(*.xls)                            odbcjt32.dll        4.0.6305.0            *.xls
    Driver do Microsoft Paradox (*.db )                         odbcjt32.dll        4.0.6305.0            *.db
    Driver para o Microsoft Visual FoxPro                       vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Access Driver (*.mdb)                             odbcjt32.dll        4.0.6305.0            *.mdb
    Microsoft Access-Treiber (*.mdb)                            odbcjt32.dll        4.0.6305.0            *.mdb
    Microsoft dBase Driver (*.dbf)                              odbcjt32.dll        4.0.6305.0            *.dbf,*.ndx,*.mdx
    Microsoft dBase VFP Driver (*.dbf)                          vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft dBase-Treiber (*.dbf)                             odbcjt32.dll        4.0.6305.0            *.dbf,*.ndx,*.mdx
    Microsoft Excel Driver (*.xls)                              odbcjt32.dll        4.0.6305.0            *.xls
    Microsoft Excel-Treiber (*.xls)                             odbcjt32.dll        4.0.6305.0            *.xls
    Microsoft FoxPro VFP Driver (*.dbf)                         vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft ODBC for Oracle                                   msorcl32.dll        2.576.3959.0 (srv03_sp2_rtm.070216-1710)  
    Microsoft Paradox Driver (*.db )                            odbcjt32.dll        4.0.6305.0            *.db
    Microsoft Paradox-Treiber (*.db )                           odbcjt32.dll        4.0.6305.0            *.db
    Microsoft Text Driver (*.txt; *.csv)                        odbcjt32.dll        4.0.6305.0            *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Text-Treiber (*.txt; *.csv)                       odbcjt32.dll        4.0.6305.0            *.,*.asc,*.csv,*.tab,*.txt,*.csv
    Microsoft Visual FoxPro Driver                              vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    Microsoft Visual FoxPro-Treiber                             vfpodbc.dll         1.0.2.0               *.dbf,*.cdx,*.idx,*.fpt
    SQL Server                                                  sqlsrv32.dll        2000.086.3959.00 (srv03_sp2_rtm.070216-1710)  


--------[ Debug - PCI ]-------------------------------------------------------------------------------------------------

    B00 D00 F00:  ATI RS690(M) Chipset - Host Bridge
                  
      Offset 00:  02 10 10 79  06 00 20 22  00 00 00 06  00 40 00 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 6D 82 
      Offset 30:  00 00 00 00  C4 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  42 20 05 00 
      Offset 50:  43 10 6D 82  FF 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  5F 00 00 00  00 00 00 00  00 02 20 00  98 F8 01 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  C0 43 00 00  95 00 00 03  20 01 10 00  03 26 00 00 
      Offset 90:  00 00 00 38  40 C5 40 E4  00 D0 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  07 01 00 00  49 01 10 07 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  08 00 80 01  60 00 11 11  D0 00 00 00 
      Offset D0:  25 05 65 00  02 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  90 00 00 00  F7 FF FE FF 
      Offset F0:  00 00 00 00  00 80 80 00  00 00 00 00  00 00 00 00 

    B00 D01 F00:  PCI standard PCI-to-PCI bridge [1002-7912] [NoDB]
                  
      Offset 00:  02 10 12 79  07 00 30 02  00 00 04 06  00 63 01 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 01 01 44  D1 D1 20 22 
      Offset 20:  A0 FD B0 FD  01 F0 F1 F7  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  44 00 00 00  00 00 00 00  FF 00 08 00 
      Offset 40:  00 00 00 00  08 B0 03 A8  00 00 00 00  02 10 12 79 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  0D 00 00 00  02 10 12 79  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D07 F00:  ATI RS690(M) Chipset - PCI Express Port 3
                  
      Offset 00:  02 10 17 79  07 00 10 00  00 00 04 06  08 00 01 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 02 02 00  E1 E1 00 00 
      Offset 20:  F0 FD F0 FD  C1 FD C1 FD  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  50 00 00 00  00 00 00 00  FF 00 04 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  01 58 03 C8  00 00 00 00  10 80 41 00  20 80 00 00 
      Offset 60:  10 08 00 00  11 0C 10 04  00 00 11 30  00 00 00 00 
      Offset 70:  C0 03 48 00  00 00 01 00  00 00 00 00  00 00 00 00 
      Offset 80:  05 B0 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  0D B8 00 00  43 10 6D 82  08 00 03 A8  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  A5 00 00 00  10 0F 0B 0A  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D12 F00:  ATI SB600 - SATA Controller
                  
      Offset 00:  02 10 80 43  07 00 30 02  00 8F 01 01  00 40 00 00 
      Offset 10:  01 FF 00 00  01 FE 00 00  01 FD 00 00  01 FC 00 00 
      Offset 20:  01 FB 00 00  00 F0 02 FE  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  60 00 00 00  00 00 00 00  16 01 00 00 
      Offset 40:  10 00 80 02  01 00 10 00  01 00 00 00  00 00 00 00 
      Offset 50:  05 00 84 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  01 00 22 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  12 00 10 00  0F 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  06 00 00 2C  D5 00 B4 00  D5 00 B4 00 
      Offset 90:  D5 00 B4 00  D5 00 B4 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 78 00 00  00 00 00 00  00 78 00 00 
      Offset B0:  00 00 00 00  00 78 00 00  00 00 00 00  00 78 00 00 
      Offset C0:  00 20 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F00:  ATI SB600 - USB Controller
                  
      Offset 00:  02 10 87 43  07 00 A0 02  00 10 03 0C  08 40 80 00 
      Offset 10:  00 E0 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  10 01 00 00 
      Offset 40:  80 1F 00 00  0A 84 B7 18  07 35 00 00  00 00 00 00 
      Offset 50:  00 8C 00 00  00 00 00 00  10 32 54 76  98 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  FF 00 00 80  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F01:  ATI SB600 - USB Controller
                  
      Offset 00:  02 10 88 43  07 00 A0 02  00 10 03 0C  08 40 00 00 
      Offset 10:  00 D0 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  11 02 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F02:  ATI SB600 - USB Controller
                  
      Offset 00:  02 10 89 43  07 00 A0 02  00 10 03 0C  08 40 00 00 
      Offset 10:  00 C0 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F03:  ATI SB600 - USB Controller
                  
      Offset 00:  02 10 8A 43  07 00 A0 02  00 10 03 0C  08 40 00 00 
      Offset 10:  00 B0 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  11 02 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F04:  ATI SB600 - USB Controller
                  
      Offset 00:  02 10 8B 43  07 00 A0 02  00 10 03 0C  08 40 00 00 
      Offset 10:  00 A0 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  12 03 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D13 F05:  ATI SB600 - USB 2.0 Controller
                  
      Offset 00:  02 10 86 43  07 00 B0 02  00 20 03 0C  08 40 00 00 
      Offset 10:  00 90 02 FE  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  C0 00 00 00  00 00 00 00  13 04 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  40 00 0E 10  01 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  20 20 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  01 00 00 00  00 00 00 C0  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  01 E4 02 7E  00 00 40 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  0A 00 E0 20  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F00:  ATI SB600 - SMBus Controller
                  
      Offset 00:  02 10 85 43  FF FF FF FF  14 00 05 0C  00 00 80 00 
      Offset 10:  01 0B 00 00  FF FF FF FF  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  B0 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  D4 39 00 04  00 00 00 00  0F FF 00 00  00 00 00 00 
      Offset 50:  F0 01 F0 08  F0 0F F0 07  11 0B F0 0F  00 00 00 00 
      Offset 60:  01 00 07 06  BF FF 9E 8F  3F 90 00 00  20 00 00 00 
      Offset 70:  00 01 00 00  08 00 C0 FE  FF 6E 00 00  00 00 F0 0F 
      Offset 80:  F0 0A F0 0F  00 00 00 00  00 00 00 00  8C 00 00 80 
      Offset 90:  01 0B 00 00  F9 CE FF 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 FF FF  FF FF F0 08  FF FD 02 02  16 7B 20 18 
      Offset B0:  08 00 02 A8  00 00 00 00  00 00 00 00  F0 0F 08 1A 
      Offset C0:  FF FF FF FF  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 01 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  20 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  D8 0C 00 00  00 00 44 00  00 00 00 00  55 00 E0 01 

    B00 D14 F01:  ATI SB600 - IDE Controller
                  
      Offset 00:  02 10 8C 43  05 00 20 02  00 8A 01 01  00 40 00 00 
      Offset 10:  01 00 00 00  01 00 00 00  01 00 00 00  01 00 00 00 
      Offset 20:  01 F9 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  FF 01 00 00 
      Offset 40:  99 99 00 00  FF FF 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 40 00  10 2C 01 07  01 00 00 00  FF FF 0F 00 
      Offset 70:  05 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F03:  ATI SB600 - PCI-LPC Bridge
                  
      Offset 00:  02 10 8D 43  0F 00 20 02  00 00 01 06  00 00 80 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 EF 81 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  04 00 00 00  FF FF FF FF  3F FF 42 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  20 02 00 00  0E 00 0F 00  B0 FF FF FF 
      Offset 70:  67 45 23 01  00 00 00 00  00 00 00 00  05 00 00 00 
      Offset 80:  08 00 03 A8  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D14 F04:  ATI SB600 - PCI-PCI Bridge
                  
      Offset 00:  02 10 84 43  27 00 A0 02  00 01 04 06  00 40 81 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 03 03 40  F0 00 80 22 
      Offset 20:  F0 FF 00 00  F0 FF 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  26 00 3C FF  00 00 00 00  0C 01 3F D1  00 00 00 00 
      Offset 50:  01 00 00 00  08 00 03 A8  00 00 00 00  85 00 FF FF 
      Offset 60:  CA 0E 17 00  BA 18 10 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  01 00 02 06 
      Offset E0:  00 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F00:  AMD Hammer - HyperTransport Technology Configuration
                  
      Offset 00:  22 10 00 11  00 00 10 00  00 00 00 06  00 00 80 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  80 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 50:  01 01 01 00  01 01 01 00  01 01 01 00  01 01 01 00 
      Offset 60:  00 00 00 00  E4 00 00 00  0F CC 21 0F  0C 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  08 00 01 21  20 00 11 11  22 05 35 80  02 00 00 00 
      Offset 90:  78 01 70 01  00 00 03 00  07 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F01:  AMD Hammer - Address Map
                  
      Offset 00:  22 10 01 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  03 00 00 00  00 00 3F 00  00 00 00 00  01 00 00 00 
      Offset 50:  00 00 00 00  02 00 00 00  00 00 00 00  03 00 00 00 
      Offset 60:  00 00 00 00  04 00 00 00  00 00 00 00  05 00 00 00 
      Offset 70:  00 00 00 00  06 00 00 00  00 00 00 00  07 00 00 00 
      Offset 80:  03 0A 00 00  00 0B 00 00  03 00 F0 00  80 FF F7 00 
      Offset 90:  03 00 40 00  00 FF DF 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  03 00 F8 00  00 02 FE 00 
      Offset B0:  03 00 E0 00  80 3F E0 00  00 00 00 00  00 00 00 00 
      Offset C0:  13 C0 00 00  00 F0 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  03 00 00 03  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F02:  AMD Hammer - DRAM Controller
                  
      Offset 00:  22 10 02 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  01 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 50:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  E0 3F 38 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  46 00 00 00  00 00 00 00 
      Offset 80:  02 00 00 00  00 00 00 00  24 C2 6A 5D  20 13 12 00 
      Offset 90:  10 0C 01 00  5A 80 00 A7  24 00 00 80  20 22 20 00 
      Offset A0:  EF 02 00 5D  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  54 19 3C F6  89 00 00 00  0F 7C 0C 0B  02 25 00 64 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  2E C3 0D 40  CE 94 42 00  5E 8C 0C 00  5E 9C 4C C1 
      Offset E0:  AE EC 4D CE  88 C4 83 B0  3F 0E 19 0C  4E A1 8F 69 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B00 D18 F03:  AMD Hammer - Miscellaneous Control
                  
      Offset 00:  22 10 03 11  00 00 00 00  00 00 00 06  00 00 80 00 
      Offset 10:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 30:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 40:  FF 3B 04 00  40 00 10 02  00 00 00 00  00 00 00 00 
      Offset 50:  70 FF 81 57  91 00 00 00  00 00 00 00  40 5A 0F 3B 
      Offset 60:  0C 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  11 01 32 51  21 40 30 50  00 2A 00 08  1C 21 00 00 
      Offset 80:  00 00 07 23  13 21 13 21  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  2C 3C 00 00  00 48 86 12  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  01 A7 0D 00  00 00 80 08  25 26 26 00 
      Offset E0:  00 00 00 00  32 23 00 00  19 05 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  F2 0F 07 00 

    B01 D05 F00:  ATI RS690 Chipset - Video Adapter
                  
      Offset 00:  02 10 1E 79  07 00 10 00  00 00 00 03  08 40 00 00 
      Offset 10:  0C 00 00 F0  00 00 00 00  04 00 BF FD  00 00 00 00 
      Offset 20:  01 DE 00 00  00 00 A0 FD  00 00 00 00  43 10 6D 82 
      Offset 30:  00 00 00 00  50 00 00 00  00 00 00 00  12 01 00 00 
      Offset 40:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 6D 82 
      Offset 50:  01 80 02 06  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 70:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  05 00 80 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 90:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset A0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset B0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 

    B02 D00 F00:  Realtek RTL8168/8111 PCI-E Gigabit Ethernet Adapter
                  
      Offset 00:  EC 10 68 81  07 00 10 00  01 00 00 02  08 00 00 00 
      Offset 10:  01 EC 00 00  00 00 00 00  04 F0 FF FD  00 00 00 00 
      Offset 20:  00 00 00 00  00 00 00 00  00 00 00 00  43 10 AA 81 
      Offset 30:  00 00 00 00  40 00 00 00  00 00 00 00  13 01 00 00 
      Offset 40:  01 48 C2 F7  00 00 00 00  03 50 00 00  00 00 00 00 
      Offset 50:  05 60 82 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 60:  10 84 01 00  23 7F 00 00  10 58 10 00  11 F4 03 00 
      Offset 70:  00 00 11 10  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset 80:  00 00 00 00  09 00 4C 01  01 1C 02 00  FB FF FF 11 
      Offset 90:  08 30 00 00  1A 9A 09 00  5D 11 0F 00  B2 0F 00 00 
      Offset A0:  02 28 FF 01  00 00 00 00  00 08 00 00  03 00 03 00 
      Offset B0:  00 40 00 00  FF 3F FF 3F  FF FF 00 00  00 00 00 00 
      Offset C0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset D0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset E0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 
      Offset F0:  00 00 00 00  00 00 00 00  00 00 00 00  00 00 00 00 


--------[ Debug - Video BIOS ]------------------------------------------------------------------------------------------

    C000:0000  U.k...........................IBM............... 761295520......
    C000:0040  ........z.......09/03/07,16:50:31...........1...................
    C000:0080  .RS690.PCI_EXPRESS.DDR2...ATI Radeon Xpress ?1250? for Asus/M2A-
    C000:00C0  VM                                    ..... ...(C) 1988-2005, AT
    C000:0100  I Technologies Inc. .ATOMBIOSBK-ATI VER010.055.000.029.025534.BR
    C000:0140  25534.BIN .        .        .        .AsusM2A\config.h....$...AT
    C000:0180  OM....>.......(...C.m...*.......PCIR...y........k.7.....ATI ATOM
    C000:01C0  BIOS...$.............................V.......LP. .^..fPfQfRfSfUf
    C000:0200  VfW..................f......f........2.......*.]*..*..........z)
    C000:0240  ..)..)....C..DP. u......c.Cd.X..-..LP....^...f...... fP. .M...fX
    C000:0280  t.. f....Z..B.f_f^f]f[fZfYfX.....fPfQfRfSfUfVfW...............f.
    C000:02C0  .....f......A.2......`)f3.......f_f^f]f[fZfYfX.........F.f3..F..
    C000:0300  .F..R......BZ..........f......o.f.\.f.L.;.u...f.^.f.N...........
    C000:0340  .>...u.............f....e.....@.....B.............|..l..~.....0p
    C000:0380  .........f.............f.*f.<f...PMID...K......................f
    C000:03C0  .........................fPfR.1f...f....fZfX.fPfR.1f...f....fZfX


--------[ Debug - Unknown ]---------------------------------------------------------------------------------------------

    Motherboard     09/07/2007-690G-SB600-M2A-VM-00
    Motherboard     ASUS M2A-VM ACPI BIOS Revision 1201
    Motherboard     DMIMOBO: ASUSTeK Computer INC. M2A-VM
    Motherboard     DMISYS: System manufacturer System Product Name
    PCI/AGP         1002-7912: PCI standard PCI-to-PCI bridge [1002-7912] [NoDB]


------------------------------------------------------------------------------------------------------------------------

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

