EvLog report for ALTAIR TECHNOLOGIES

Setting Value
Server name EMACHINE 
Time interval Last 24 hours
Logs Application,System,Security
Total events 136 
Excluded events  
Generated on Wed Sep 1 16:05:17 2004 

Application log for EMACHINE

Date and time Source Type ID Description
09/01/2004 11:13:43 Userenv Error 1054 Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
09/01/2004 10:53:10 AutoEnrollment Error 15 Automatic certificate enrollment for local system failed to contact the active directory 0x8007054b . The specified domain either does not exist or could not be contacted. Enrollment will not be performed.
09/01/2004 10:52:10 Userenv Error 1054 Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.
09/01/2004 10:58:12 EventSystem Warning 4356 The COM+ Event System failed to create an instance of the subscriber partition:{41E90F3E-56C1-4633-81C3-6E8BAC8BDD70}!new:{6295DF2D-35EE-11D1-8707-00C04FD93327} . CoGetObject returned HRESULT 8000401A .
09/01/2004 10:53:03 EventSystem Warning 4356 The COM+ Event System failed to create an instance of the subscriber partition:{41E90F3E-56C1-4633-81C3-6E8BAC8BDD70}!new:{6295DF2D-35EE-11D1-8707-00C04FD93327} . CoGetObject returned HRESULT 8000401A .
08/31/2004 16:40:57 Userenv Warning 1517 Windows saved user acme\asmith registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use. This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.
09/01/2004 15:58:36 ESENT Information 103 wuaueng.dll (968 ) SUS20ClientDataStore: The database engine stopped the instance (0 ).
09/01/2004 15:58:36 ESENT Information 101 wuauclt (968 ) The database engine stopped.
09/01/2004 15:53:18 ESENT Information 100 wuauclt (968 ) The database engine 5 .01 .2600 .0000 started.
09/01/2004 15:53:18 ESENT Information 102 wuaueng.dll (968 ) SUS20ClientDataStore: The database engine started a new instance (0 ).
09/01/2004 12:42:25 McUpdate Information 4550 The .DAT and Engine versions on the system (4388 and 4320 ) are the newest available.
09/01/2004 12:42:04 McUpdate Information 4570 AutoUpdate Task started.
09/01/2004 10:58:17 ESENT Information 101 wuauclt (1984 ) The database engine stopped.
09/01/2004 10:58:17 ESENT Information 103 wuaueng.dll (1984 ) SUS20ClientDataStore: The database engine stopped the instance (0 ).
09/01/2004 10:52:13 McLogEvent Information 5000 VirusScan McShield service started - scanning for 98919 viruses. Engine version : 4.3.20 .DAT version : 4388 EXTRA.DAT name : None Number of virus signatures in EXTRA.DAT : None Names of viruses that EXTRA.DAT can detect : None
09/01/2004 10:52:08 ESENT Information 102 wuaueng.dll (1984 ) SUS20ClientDataStore: The database engine started a new instance (0 ).
09/01/2004 10:52:08 ESENT Information 100 wuauclt (1984 ) The database engine 5 .01 .2600 .0000 started.
09/01/2004 10:52:04 AdisconMoniLog Information 109 The MoniLog deamon background thread was successfully started.
09/01/2004 10:52:04 AdisconMoniLog Information 105 The service was started.
08/31/2004 16:07:37 ESENT Information 101 wuauclt (2284 ) The database engine stopped.
08/31/2004 16:07:37 ESENT Information 103 wuaueng.dll (2284 ) SUS20ClientDataStore: The database engine stopped the instance (0 ).

System log for EMACHINE

Date and time Source Type ID Description
09/01/2004 14:43:28 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 239 minutes. NtpClient has no source of accurate time.
09/01/2004 12:43:25 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 119 minutes. NtpClient has no source of accurate time.
09/01/2004 11:43:27 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 59 minutes. NtpClient has no source of accurate time.
09/01/2004 11:13:23 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 30 minutes. NtpClient has no source of accurate time.
09/01/2004 10:58:22 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 15 minutes. NtpClient has no source of accurate time.
09/01/2004 10:52:12 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time.
09/01/2004 10:52:11 W32Time Error 29 The time provider NtpClient is configured to acquire time from one or more time sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes. NtpClient has no source of accurate time.
09/01/2004 10:52:11 NETLOGON Error 5719 No Domain Controller is available for domain acme due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
09/01/2004 14:43:28 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 240 minutes.
09/01/2004 12:43:25 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 120 minutes.
09/01/2004 11:43:27 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 60 minutes.
09/01/2004 11:13:28 DnsApi Warning 11165 The system failed to register host (A) resource records (RRs) for network adapter with settings: Adapter Name : {96175457-74E3-4F09-800E-1BCA1A25782D} Host Name : emachine Primary Domain Suffix : acme.local DNS server list : 192.168.7.1 Sent update to server : IP Address(es) : 192.168.7.100 The reason the system could not register these RRs was because the DNS server contacted refused the update request. The reasons for this might be (a) you are not allowed to update the specified DNS domain name, or (b) because the DNS server authoritative for this name does not support the DNS dynamic update protocol. To register the DNS host (A) resource records using the specific DNS domain name and IP addresses for this adapter, contact your DNS server or network systems administrator.
09/01/2004 11:13:23 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 30 minutes.
09/01/2004 10:58:22 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 15 minutes.
09/01/2004 10:58:10 DnsApi Warning 11191 The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : {32FC69C6-2DE6-48C1-BCF4-F068CEE9283B} Host Name : emachine Adapter-specific Domain Suffix : acme.local DNS server list : 192.168.0.40 Sent update to server : IP Address : 192.1.1.1 The system could not remove these PTR RRs because because of a system problem. For specific error code, see the record data displayed below.
09/01/2004 10:58:10 DnsApi Warning 11197 The system failed to update and remove host (A) resource records (RRs) for network adapter with settings: Adapter Name : {32FC69C6-2DE6-48C1-BCF4-F068CEE9283B} Host Name : emachine Primary Domain Suffix : acme.local DNS server list : 192.168.0.40 Sent update to server : IP Address(es) : 192.168.0.100 The reason the update request failed was because of a system problem. For specific error code, see the record data displayed below.
09/01/2004 10:57:29 W32Time Warning 36 The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized.
09/01/2004 10:53:02 DnsApi Warning 11191 The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : {32FC69C6-2DE6-48C1-BCF4-F068CEE9283B} Host Name : emachine Adapter-specific Domain Suffix : acme.local DNS server list : 192.168.0.40 Sent update to server : IP Address : 192.1.1.1 The system could not remove these PTR RRs because because of a system problem. For specific error code, see the record data displayed below.
09/01/2004 10:53:00 DnsApi Warning 11195 The system failed to update and remove host (A) resource records (RRs) for network adapter with settings: Adapter Name : {32FC69C6-2DE6-48C1-BCF4-F068CEE9283B} Host Name : emachine Primary Domain Suffix : acme.local DNS server list : 192.168.0.40 Sent update to server : IP Address(es) : 192.168.0.100 The request to remove these records failed because the DNS server refused the update request. The cause of this might be that either (a) this computer is not allowed to update the DNS domain name specified by these settings, or (b) because the DNS server authorized to perform updates for the zone that contains these RRs does not support the DNS dynamic update protocol.
09/01/2004 10:52:12 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 15 minutes.
09/01/2004 10:52:11 W32Time Warning 14 The time provider NtpClient was unable to find a domain controller to use as a time source. NtpClient will try again in 15 minutes.
09/01/2004 13:18:18 Application Popup Information 26 Application popup: ISAPreprocessingComponent.exe - Common Language Runtime Debugging Services : Application has generated an exception that could not be handled. Process id=0xd78 (3448), Thread id=0xa10 (2576). Click OK to terminate the application. Click CANCEL to debug the application.
09/01/2004 13:00:35 Application Popup Information 26 Application popup: ISAPreprocessingComponent.exe - Common Language Runtime Debugging Services : Application has generated an exception that could not be handled. Process id=0xf60 (3936), Thread id=0xeb4 (3764). Click OK to terminate the application. Click CANCEL to debug the application.
09/01/2004 11:13:57 Service Control Manager Information 7036 The IMAPI CD-Burning COM Service service entered the stopped state.
09/01/2004 11:13:51 Service Control Manager Information 7036 The SSDP Discovery Service service entered the running state.
09/01/2004 11:13:51 Service Control Manager Information 7035 The SSDP Discovery Service service was successfully sent a start control.
09/01/2004 11:13:51 Service Control Manager Information 7036 The IMAPI CD-Burning COM Service service entered the running state.
09/01/2004 11:13:51 Service Control Manager Information 7035 The IMAPI CD-Burning COM Service service was successfully sent a start control.
09/01/2004 11:02:13 Service Control Manager Information 7036 The Remote Desktop Help Session Manager service entered the stopped state.
09/01/2004 10:58:13 Service Control Manager Information 7036 The Windows Image Acquisition (WIA) service entered the running state.
09/01/2004 10:58:11 BROWSER Information 8033 The browser has forced an election on network \Device\NetBT_Tcpip_{96175457-74E3-4F09-800E-1BCA1A25782D} because a master browser was stopped.
09/01/2004 10:52:58 Service Control Manager Information 7036 The McShield service entered the running state.
09/01/2004 10:52:58 Service Control Manager Information 7036 The Terminal Services service entered the running state.
09/01/2004 10:52:58 Service Control Manager Information 7035 The NaiFiltr service was successfully sent a start control.
09/01/2004 10:52:58 Service Control Manager Information 7035 The McShield service was successfully sent a start control.
09/01/2004 10:52:58 Service Control Manager Information 7035 The Terminal Services service was successfully sent a start control.
09/01/2004 10:51:46 EventLog Information 6005 The Event log service was started.
09/01/2004 10:51:46 EventLog Information 6009 Microsoft (R) Windows (R) 5.01. 2600 Service Pack 1 Uniprocessor Free .
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check: Regs
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check: Regs
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check:
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check:
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check:
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check: Regs
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check:
09/01/2004 10:51:40 Application Popup Information 26 Application popup: : Machine Check: Regs
09/01/2004 10:51:38 redbook Information 10 This drive has not been shown to support digital audio playback.
08/31/2004 16:41:14 EventLog Information 6006 The Event log service was stopped.
08/31/2004 16:40:36 Service Control Manager Information 7036 The McShield service entered the stopped state.
08/31/2004 16:40:36 Service Control Manager Information 7035 The McShield service was successfully sent a stop control.
08/31/2004 16:11:48 Service Control Manager Information 7036 The Remote Desktop Help Session Manager service entered the stopped state.

Security log for EMACHINE

Date and time Source Type ID Description
09/01/2004 14:26:08 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 14:26:00 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 14:25:41 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:13:03 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:12:55 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:12:01 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:11:02 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:10:45 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:10:01 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:01:12 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:01:06 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:01:06 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:01:05 Security Failure Audit 598 Protection of auditable protected data. Data Description: Enterprise Credential Set Key Identifier: Protected Data Flags: 0x20000000 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:01:05 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 13:00:56 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 11:19:22 Security Failure Audit 598 Protection of auditable protected data. Data Description: Enterprise Credential Set Key Identifier: Protected Data Flags: 0x20000000 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 11:13:48 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 11:13:48 Security Failure Audit 598 Protection of auditable protected data. Data Description: Key Identifier: Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 11:13:42 Security Failure Audit 599 Unprotection of auditable protected data. Data Description: Enterprise Credential Set Key Identifier: 46f0e4e0-0056-4dcf-8f48-04c53e1a698d Protected Data Flags: 0x0 Protection Algorithms: 3DES-168 , SHA1-160 Failure Reason: 0x2
09/01/2004 11:13:41 Security Failure Audit 680 Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: asmith@acme.local Source Workstation: EMACHINE 0xC0000064
09/01/2004 10:58:10 Security Failure Audit 615 IPSec Services: IPSec Services failed to get the complete list of network interfaces on the machine. This can be a potential security hazard to the machine since some of the network interfaces may not get the protection as desired by the applied IPSec filters. Please run IPSec monitor snap-in to further diagnose the problem.
09/01/2004 12:29:57 Security Success Audit 528 Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 11:38:18 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: KSecDD
09/01/2004 11:13:50 Security Success Audit 528 Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 11:13:41 Security Success Audit 528 Successful Logon: User Name: asmith Domain: acme Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 2 Logon Process: User32 Authentication Package: Negotiate Workstation Name: EMACHINE Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 11:13:39 Security Success Audit 528 Successful Logon: User Name: asmith Domain: acme Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 11 Logon Process: User32 Authentication Package: Negotiate Workstation Name: EMACHINE Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 11:13:39 Security Success Audit 538 User Logoff: User Name: asmith Domain: acme Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 11
09/01/2004 10:53:14 Security Success Audit 528 Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:52:12 Security Success Audit 629 User Account Disabled: Target Account Name: HelpAssistant Target Domain: EMACHINE Target Account ID: %{S-1-5-21-1563972592-4232377176-2666036622-1004} Caller User Name: EMACHINE$ Caller Domain: acme Caller Logon ID: (0x0,0x3E7)
09/01/2004 10:52:11 Security Success Audit 540 Successful Network Logon: User Name: HelpAssistant Domain: EMACHINE Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 8 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: EMACHINE Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:52:11 Security Success Audit 609 User Right Removed: User Right: - Removed From: %{S-1-5-21-1563972592-4232377176-2666036622-1004} Removed By: User Name: EMACHINE$ Domain: acme Logon ID: (0x0,0x3E7)
09/01/2004 10:52:11 Security Success Audit 538 User Logoff: User Name: HelpAssistant Domain: EMACHINE Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 8
09/01/2004 10:52:11 Security Success Audit 680 Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0 Logon account: HelpAssistant Source Workstation: EMACHINE 0x0
09/01/2004 10:52:11 Security Success Audit 622 System Security Access Removed: Access Removed: SeNetworkLogonRight Account Modified: %{S-1-5-21-1563972592-4232377176-2666036622-1004} Removed By: User Name: EMACHINE$ Domain: acme Logon ID: (0x0,0xnnnn)
09/01/2004 10:52:09 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: RASMAN
09/01/2004 10:52:07 Security Success Audit 621 System Security Access Granted: Access Granted: SeNetworkLogonRight Account Modified: %{S-1-5-21-1563972592-4232377176-2666036622-1004} Assigned By: User Name: EMACHINE$ Domain: acme Logon ID: (0x0,0xnnnn)
09/01/2004 10:52:07 Security Success Audit 626 User Account Enabled: Target Account Name: HelpAssistant Target Domain: EMACHINE Target Account ID: %{S-1-5-21-1563972592-4232377176-2666036622-1004} Caller User Name: EMACHINE$ Caller Domain: acme Caller Logon ID: (0x0,0x3E7)
09/01/2004 10:52:07 Security Success Audit 528 Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:52:04 Security Success Audit 540 Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:52:04 Security Success Audit 615 IPSec Services: IPSec Services has started successfully.
09/01/2004 10:52:03 Security Success Audit 528 Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:52:03 Security Success Audit 528 Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:51:47 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: LAN Manager Workstation Service
09/01/2004 10:51:47 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: CHAP
09/01/2004 10:51:47 Security Success Audit 528 Successful Logon: User Name: LOCAL SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:51:46 Security Success Audit 518 An notification package has been loaded by the Security Account Manager. This package will be notified of any account or password changes. Notification Package Name: scecli
09/01/2004 10:51:46 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: KSecDD
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\kerberos.dll : Kerberos
09/01/2004 10:51:46 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: KSecDD
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\msv1_0.dll : MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\LSASRV.dll : Negotiate
09/01/2004 10:51:46 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: Winlogon
09/01/2004 10:51:46 Security Success Audit 528 Successful Logon: User Name: NETWORK SERVICE Domain: NT AUTHORITY Logon ID: (0x0,0xnnnn) Logon type: Logon Type: 5 Logon Process: Advapi Authentication Package: Negotiate Workstation Name: Logon GUID: {00000000-0000-0000-0000-000000000000}
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\msv1_0.dll : NTLM
09/01/2004 10:51:46 Security Success Audit 512 Windows is starting up.
09/01/2004 10:51:46 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: DCOMSCM
09/01/2004 10:51:46 Security Success Audit 612 Audit Policy Change: New Policy: Success Failure + + Logon/Logoff - - Object Access - - Privilege Use + + Account Management + + Policy Change + + System - - Detailed Tracking + + Directory Service Access + + Account Logon Changed By: User Name: EMACHINE$ Domain Name: acme Logon ID: (0x0,0x3E7)
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\schannel.dll : Microsoft Unified Security Protocol Provider
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\wdigest.dll : WDigest
09/01/2004 10:51:46 Security Success Audit 514 An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. Authentication Package Name: C:\WINDOWS\system32\schannel.dll : Schannel
09/01/2004 10:51:46 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: Winlogon\MSGina
08/31/2004 16:41:00 Security Success Audit 513 Windows is shutting down. All logon sessions will be terminated by this shutdown.
08/31/2004 16:40:29 Security Success Audit 551 User initiated logoff: User Name: asmith Domain: acme Logon ID: (0x0,0xnnnn)
08/31/2004 16:11:00 Security Success Audit 515 A trusted logon process has registered with the Local Security Authority. This logon process will be trusted to submit logon requests. Logon Process Name: KSecDD

Send your suggestions to EvLog developers - Altair Technologies!

Report generated with EvLog version 1.00 The analysis took 1 second.

Troubleshooting resources