All Events Summary - File Output - Adiscon LogAnalyzer

37
All Events Summary - File Output List of used filters Number Messagetype == 3 Report Summary Event Summary Total Events 2293 INFO 1173 NOTICE 1012 WARNING 79 ERR 29 Computer Summary XPTEST (1029), W2003R2 (980), W2KTESTING (247), MACHINENAME (37), Events Consolidated per Host XPTEST No. First Event Last Event Process Type Event ID Count 1 2008-09-16 15:14:42 2008-09-16 15:17:58 VMTools INFO 105 29 Description The service was started. 1/37

Transcript of All Events Summary - File Output - Adiscon LogAnalyzer

All Events Summary - File Output

List of used filtersNumber Messagetype == 3

Report Summary

Event SummaryTotal Events 2293INFO 1173NOTICE 1012WARNING 79ERR 29

Computer SummaryXPTEST(1029), W2003R2(980), W2KTESTING(247), MACHINENAME(37),

Events Consolidated per Host

XPTEST

No. First Event Last Event Process TypeEventID

Count

1 2008-09-1615:14:42

2008-09-1615:17:58

VMTools INFO 105 29

Description The service was started.

1/37

2 2008-09-1615:14:48

2008-09-1615:14:49

Windows Update Agent INFO 18 23

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 16. August 2006 at 03:00: - Security Updatefor Windows XP (KB890859) - Security Update for Windows XP(KB914389) - Security Update for Windows XP (KB920683) -Security Update for Windows XP (KB908519) - Update for WindowsXP (KB894391) - Cumulative Security Update for Outlook Expressfor Windows XP (KB911567) - Security Update for Windows XP(KB896428) - Security Update for Windows XP (KB913580) -Security Update for Windows XP (KB905749) - Security Update forWindows XP (KB908531) - Security Update for Windows XP(KB904706) - Update for Windows XP (KB916595) - SecurityUpdate for Windows XP (KB912919) - Security Update for WindowsXP (KB900725) - Security Update for Windows XP (KB888302) -Security Update for Windows XP (KB917422) - Security Update forWindows XP (KB901214) - Security Update for Windows XP(KB917953) - Security Update for Windows XP (KB905414) -Security Update for Windows XP (KB917344) - Security Update forWindows XP (KB914388) - Security Update for Windows XP(KB899589) - Security Update

3 2008-09-1615:14:42

2008-09-1615:17:58

SecurityCenter INFO 1800 17

Description The Windows Security Center Service has started.4 2008-09-16

15:14:452008-09-1615:14:58

Service Control Manager INFO 7036 16

Description The SSDP Discovery Service service entered the running state.5 2008-09-16

15:14:452008-09-1615:14:57

EventLog INFO 6005 16

Description The Event log service was started.6 2008-09-16

15:14:452008-09-1615:14:57

Service Control Manager INFO 7035 16

Description The SSDP Discovery Service service was successfully sent a startcontrol.

7 2008-09-1615:14:46

2008-09-1615:14:57

Service Control Manager INFO 7035 15

Description The Terminal Services service was successfully sent a start control.8 2008-09-16

15:14:452008-09-1615:14:57

Service Control Manager INFO 7036 15

Description The Terminal Services service entered the running state.9 2008-09-16

15:14:462008-09-1615:14:57

EventLog INFO 6006 15

Description The Event log service was stopped.10 2008-09-16

15:14:452008-09-1615:14:57

Service Control Manager INFO 7035 15

Description The Network Location Awareness (NLA) service was successfullysent a start control.

2/37

11 2008-09-1615:14:45

2008-09-1615:14:57

Service Control Manager INFO 7036 15

Description The Network Location Awareness (NLA) service entered the runningstate.

12 2008-09-1615:14:46

2008-09-1615:14:57

Service Control Manager INFO 7036 14

Description The Application Layer Gateway Service service entered the runningstate.

13 2008-09-1615:14:46

2008-09-1615:14:57

EventLog INFO 6009 14

Description Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 UniprocessorFree.

14 2008-09-1615:14:46

2008-09-1615:14:57

Service Control Manager INFO 7035 14

Description The Application Layer Gateway Service service was successfullysent a start control.

15 2008-09-1615:14:46

2008-09-1615:14:58

Service Control Manager INFO 7035 13

Description The Windows Installer service was successfully sent a start control.16 2008-09-16

15:14:462008-09-1615:14:58

Service Control Manager INFO 7036 13

Description The Windows Installer service entered the running state.17 2008-09-16

15:14:462008-09-1615:14:58

Service Control Manager INFO 7036 13

Description The Windows Installer service entered the stopped state.18 2008-09-16

15:14:522008-09-1615:14:52

Windows Update Agent INFO 18 13

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 7. November 2007 at 03:00: - Security Updatefor Windows XP (KB928843) - Security Update for Flash Player(KB923789) - Security Update for Windows XP (KB923689) -Update for Windows XP (KB930916) - Security Update for WindowsXP (KB920213) - Security Update for Windows XP (KB926255) -Security Update for Windows XP (KB918118) - Update for WindowsXP (KB922582) - Security Update for Windows XP (KB923191) -Security Update for Windows XP (KB932168) - Security Update forMicrosoft .NET Framework, Version 2.0 (KB928365) - SecurityUpdate for Windows XP (KB919007) - Security Update for WindowsXP (KB930178) - Update for Windows XP (KB920872) - SecurityUpdate for Windows XP (KB926436) - Security Update for WindowsXP (KB925902) - Security Update for Microsoft XML Core Services6.0 and Microsoft XML Core Services 6.0 Service Pack 1(KB933579) - Security Update for Windows Media Player 6.4(KB925398) - Update for Windows XP (KB927891) - SecurityUpdate for Windows XP (KB924496) - Security Update for WindowsMedia Pla

3/37

19 2008-09-1615:14:47

2008-09-1615:14:47

Service Control Manager INFO 7035 12

Description The .NET Runtime Optimization Service v2.0.50727_X86 servicewas successfully sent a pause control.

20 2008-09-1615:14:44

2008-09-1615:17:58

WinMgmt WARNING 5603 12

Description A provider, TPAutoConnDLL, has been registered in the WMInamespace, Root\ThinPrint, but did not specify the HostingModelproperty. This provider will be run using the LocalSystem account.This account is privileged and the provider may cause a securityviolation if it does not correctly impersonate user requests. Ensurethat provider has been reviewed for security behavior and updatethe HostingModel property of the provider registration to an accountwith the least privileges possible for the required functionality.

21 2008-09-1615:14:41

2008-09-1615:17:58

LoadPerf INFO 1000 11

Description Performance counters for the WmiApRpl (WmiApRpl) service wereloaded successfully. The Record Data contains the new indexvalues assigned to this service.

22 2008-09-1615:14:41

2008-09-1615:17:58

LoadPerf INFO 1001 10

Description Performance counters for the WmiApRpl (WmiApRpl) service wereremoved successfully. The Record Data contains the new values ofthe system Last Counter and Last Help registry entries.

23 2008-09-1615:14:47

2008-09-1615:14:57

Service Control Manager INFO 7036 10

Description The HTTP SSL service entered the running state.24 2008-09-16

15:14:472008-09-1615:14:57

Service Control Manager INFO 7035 10

Description The HTTP SSL service was successfully sent a start control.25 2008-09-16

15:14:462008-09-1615:14:56

Service Control Manager INFO 7036 6

Description The VMware Tools Service service entered the stopped state.26 2008-09-16

15:14:422008-09-1615:17:58

MsiInstaller INFO 1005 5

Description The Windows Installer initiated a system restart to complete orcontinue the configuration of 'VMware Tools'.

27 2008-09-1615:14:47

2008-09-1615:14:53

Service Control Manager INFO 7036 5

Description The .NET Runtime Optimization Service v2.0.50727_X86 serviceentered the running state.

28 2008-09-1615:14:44

2008-09-1615:17:58

VMTools INFO 108 4

Description The service was stopped.29 2008-09-16

15:14:442008-09-1615:14:45

crypt32 INFO 7 4

Description Successful auto update retrieval of third-party root list sequencenumber from:

4/37

30 2008-09-1615:14:52

2008-09-1615:14:52

Windows Update Agent INFO 18 4

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 7. November 2007 at 03:00: - Security Updatefor Windows XP (KB928843) - Security Update for Windows XP(KB935839) - Security Update for Flash Player (KB923789) -Security Update for Windows XP (KB923689) - Update for WindowsXP (KB930916) - Security Update for Windows XP (KB935840) -Update for Windows XP (KB933360) - Security Update for WindowsXP (KB920213) - Security Update for Windows XP (KB938127) -Security Update for Windows XP (KB926255) - Security Update forWindows XP (KB918118) - Security Update for Outlook Express forWindows XP (KB941202) - Update for Windows XP (KB922582) -Security Update for Windows XP (KB923191) - Security Update forWindows XP (KB932168) - Security Update for Microsoft .NETFramework, Version 2.0 (KB928365) - Security Update for WindowsXP (KB919007) - Security Update for Windows XP (KB930178) -Update for Windows XP (KB920872) - Security Update for WindowsXP (KB926436) - Cumulative Security Update for Outlook Expressfor Windows XP (KB929123) - Security Update for Windows

31 2008-09-1615:14:52

2008-09-1615:14:53

Windows Update Agent INFO 18 4

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Donnerstag, 17. Januar 2008 at 11:01: - Security Updatefor Windows XP (KB928843) - Security Update for Windows XP(KB935839) - Security Update for Flash Player (KB923789) -Security Update for Windows XP (KB923689) - Update for WindowsXP (KB930916) - Security Update for Windows XP (KB935840) -Update for Windows XP (KB933360) - Security Update for WindowsXP (KB920213) - Security Update for Windows XP (KB938127) -Security Update for Windows XP (KB926255) - Security Update forWindows XP (KB918118) - Security Update for Outlook Express forWindows XP (KB941202) - Update for Windows XP (KB922582) -Security Update for Windows XP (KB923191) - Security Update forWindows XP (KB932168) - Security Update for Microsoft .NETFramework, Version 2.0 (KB928365) - Security Update for WindowsXP (KB919007) - Security Update for Windows XP (KB930178) -Update for Windows XP (KB920872) - Security Update for WindowsXP (KB926436) - Cumulative Security Update for Outlook Expressfor Windows XP (KB929123) - Security Update for Windows

32 2008-09-1615:14:46

2008-09-1615:14:56

Service Control Manager INFO 7035 4

Description The VMware Tools Service service was successfully sent a startcontrol.

5/37

33 2008-09-1615:14:46

2008-09-1615:14:56

BROWSER INFO 8033 4

Description The browser has forced an election on network\Device\NetBT_Tcpip_{3B4CAD29-2B55-4354-8682-6F3DF89C5DE2} because a master browser wasstopped.

34 2008-09-1615:14:44

2008-09-1615:17:58

MsiInstaller INFO 11728 4

Description Product: VMware Tools -- Configuration completed successfully.35 2008-09-16

15:14:452008-09-1615:14:57

Service Control Manager INFO 7035 4

Description The Remote Access Connection Manager service was successfullysent a start control.

36 2008-09-1615:14:46

2008-09-1615:14:56

Service Control Manager INFO 7036 4

Description The VMware Tools Service service entered the running state.37 2008-09-16

15:14:422008-09-1615:14:43

Visual Studio 2005 Remote Debugger INFO 1000 4

Description XPTEST\Administrator connected.38 2008-09-16

15:14:452008-09-1615:17:58

AdisconWINSyslog INFO 118 4

Description WinSyslog Service is running in trial mode. 29 days left39 2008-09-16

15:14:512008-09-1615:14:56

Print WARNING 20 3

Description Printer Driver TP Output Gateway for Windows NT x86 Version-3was added or updated. Files:- TPPRN.DLL, TPPrnUI.DLL,TPOG.bin, TPOG.hlp.

40 2008-09-1615:14:55

2008-09-1615:14:57

Service Control Manager INFO 7036 3

Description The Remote Access Connection Manager service entered therunning state.

41 2008-09-1615:14:44

2008-09-1615:14:45

crypt32 INFO 2 3

Description Successful auto update retrieval of third-party root list cab from: 42 2008-09-16

15:14:422008-09-1615:14:44

ASP.NET 2.0.50727.0 WARNING 1020 3

Description Updates to the IIS metabase were aborted because IIS is either notinstalled or is disabled on this machine. To configure ASP.NET torun in IIS, please install or enable IIS and re-register ASP.NET usingaspnet_regiis.exe /i.

43 2008-09-1615:14:42

2008-09-1615:14:44

LoadPerf INFO 1000 3

Description Performance counters for the ASP.NET_2.0.50727(ASP.NET_2.0.50727) service were loaded successfully. TheRecord Data contains the new index values assigned to this service.

44 2008-09-1615:14:55

2008-09-1615:14:57

Service Control Manager INFO 7036 3

Description The Telephony service entered the running state.

6/37

45 2008-09-1615:14:46

2008-09-1615:14:51

Service Control Manager INFO 7036 3

Description The Background Intelligent Transfer Service service entered therunning state.

46 2008-09-1615:14:42

2008-09-1615:14:44

LoadPerf INFO 1000 3

Description Performance counters for the ASP.NET (ASP.NET) service wereloaded successfully. The Record Data contains the new indexvalues assigned to this service.

47 2008-09-1615:14:47

2008-09-1615:14:53

Service Control Manager INFO 7035 3

Description The .NET Runtime Optimization Service v2.0.50727_X86 servicewas successfully sent a start control.

48 2008-09-1615:14:49

2008-09-1615:14:54

Service Control Manager INFO 7036 3

Description The .NET Runtime Optimization Service v2.0.50727_X86 serviceentered the stopped state.

49 2008-09-1615:14:46

2008-09-1615:21:58

Windows Update Agent INFO 19 3

Description Installation Successful: Windows successfully installed the followingupdate: Automatic Updates

50 2008-09-1615:14:46

2008-09-1615:14:51

Service Control Manager INFO 7035 3

Description The Background Intelligent Transfer Service service wassuccessfully sent a start control.

51 2008-09-1615:14:51

2008-09-1615:14:56

Service Control Manager INFO 7035 3

Description The VMware Tools Service service was successfully sent a stopcontrol.

52 2008-09-1615:14:42

2008-09-1615:14:44

ASP.NET 2.0.50727.0 INFO 1017 3

Description Start registering ASP.NET (version 2.0.50727.0) (internal flag:0x00000406)

53 2008-09-1615:14:42

2008-09-1615:14:42

MsiInstaller INFO 11707 3

Description Product: Microsoft Visual Studio 2005 Professional Edition - ENU --Installation completed successfully.

54 2008-09-1615:14:46

2008-09-1615:21:58

Service Control Manager INFO 7036 3

Description The Automatic Updates service entered the running state.55 2008-09-16

15:14:432008-09-1615:14:44

LoadPerf INFO 1001 2

Description Performance counters for the ASP.NET_2.0.50727(ASP.NET_2.0.50727) service were removed successfully. TheRecord Data contains the new values of the system Last Counterand Last Help registry entries.

7/37

56 2008-09-1615:14:45

2008-09-1615:17:58

MsiInstaller INFO 11707 2

Description Product: MonitorWare Agent 5.2 - Build 348 -- Installation operationcompleted successfully.

57 2008-09-1615:14:45

2008-09-1615:14:46

EventLog INFO 6009 2

Description Microsoft (R) Windows (R) 5.01. 2600 Uniprocessor Free.58 2008-09-16

15:14:452008-09-1615:17:58

MsiInstaller INFO 11707 2

Description Product: WinSyslog 8.2 - Build 461 -- Installation operationcompleted successfully.

59 2008-09-1615:14:45

2008-09-1615:17:58

AdisconMonitoreWareAgent INFO 118 2

Description MonitorWare Agent is running in trial mode. You have 29 days leftfor evaluation. After that period, MonitorWare agent will be disabled.To purchase, please visit http://www.mwagent.com/en/.

60 2008-09-1615:14:44

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the .NET CLR Networking (.NET CLRNetworking) service are already in Performance Registry, no need tore-install again.

61 2008-09-1615:14:44

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the .NETFramework (.NETFramework)service are already in Performance Registry, no need to re-installagain.

62 2008-09-1615:14:44

2008-09-1615:14:44

MsiInstaller INFO 11728 2

Description Product: Microsoft .NET Framework 2.0 -- Configuration completedsuccessfully.

63 2008-09-1615:14:44

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the .NET CLR Data (.NET CLR Data)service are already in Performance Registry, no need to re-installagain.

64 2008-09-1615:14:44

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the .NET Data Provider for SqlServer(.NET Data Provider for SqlServer) service are already inPerformance Registry, no need to re-install again.

65 2008-09-1615:14:43

2008-09-1615:14:44

LoadPerf INFO 1001 2

Description Performance counters for the ASP.NET (ASP.NET) service wereremoved successfully. The Record Data contains the new values ofthe system Last Counter and Last Help registry entries.

8/37

66 2008-09-1615:14:44

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the .NET Data Provider for Oracle (.NETData Provider for Oracle) service are already in PerformanceRegistry, no need to re-install again.

67 2008-09-1615:14:43

2008-09-1615:14:44

LoadPerf INFO 1002 2

Description Performance counters for the aspnet_state (ASP.NET StateService) service are already in Performance Registry, no need tore-install again.

68 2008-09-1615:14:46

2008-09-1615:14:52

USER32 INFO 1074 2

Description The process msiexec.exe has initiated the restart of XPTEST for thefollowing reason: No title for this reason could be found MinorReason: 0x2 Shutdown Type: reboot Comment: The WindowsInstaller initiated a system restart to complete or continue theconfiguration of 'VMware Tools'.

69 2008-09-1615:14:47

2008-09-1615:14:47

Service Control Manager INFO 7036 2

Description The .NET Runtime Optimization Service v2.0.50727_X86 serviceentered the paused state.

70 2008-09-1615:14:54

2008-09-1615:14:54

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Freitag, 18. Januar 2008 at 03:00: - Security Update forWindows XP with Windows Media Format Runtime 9 (KB941569) -Update for Windows XP (KB942763) - Security Update for WindowsXP (KB941644) - Update for Windows XP (KB938828) - SecurityUpdate for Windows XP (KB936021) - Update for Windows XP(KB942840) - Security Update for Windows XP (KB937894)

71 2008-09-1615:14:46

2008-09-1615:14:47

Service Control Manager INFO 7035 2

Description The Windows Installer service was successfully sent a stop control.72 2008-09-16

15:14:462008-09-1615:14:47

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Dienstag, 15. August 2006 at 03:00: - Update forWindows XP (KB898461) - Microsoft Windows Installer 3.1

73 2008-09-1615:14:47

2008-09-1615:14:47

Service Control Manager INFO 7035 2

Description The .NET Runtime Optimization Service v2.0.50727_X86 servicewas successfully sent a continue control.

9/37

74 2008-09-1615:14:54

2008-09-1615:14:54

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Freitag, 18. Januar 2008 at 03:00: - Security Update forWindows XP with Windows Media Format Runtime 9 (KB941569) -Update for Windows XP (KB938828) - Security Update for WindowsXP (KB936021)

75 2008-09-1615:14:48

2008-09-1615:14:48

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 16. August 2006 at 03:00: - Security Updatefor Windows XP (KB914389) - Security Update for Windows XP(KB920683) - Security Update for Windows XP (KB908519) -Update for Windows XP (KB894391) - Cumulative Security Updatefor Outlook Express for Windows XP (KB911567) - Security Updatefor Windows XP (KB896428) - Security Update for Windows XP(KB913580) - Security Update for Windows XP (KB905749) -Security Update for Windows XP (KB908531) - Security Update forWindows XP (KB904706) - Update for Windows XP (KB916595) -Security Update for Windows XP (KB912919) - Security Update forWindows XP (KB900725) - Security Update for Windows XP(KB888302) - Security Update for Windows XP (KB917422) -Security Update for Windows XP (KB901214) - Security Update forWindows XP (KB917953) - Security Update for Windows XP(KB905414) - Security Update for Windows XP (KB917344) -Security Update for Windows XP (KB914388) - Security Update forWindows Media Player Plug-in (KB911564) - Update for WindowsXP (KB910437)

76 2008-09-1615:14:48

2008-09-1615:14:48

Service Control Manager INFO 7036 2

Description The Visual Studio 2005 Remote Debugger service entered therunning state.

77 2008-09-1615:14:48

2008-09-1615:14:48

Service Control Manager INFO 7035 2

Description The Visual Studio 2005 Remote Debugger service was successfullysent a start control.

10/37

78 2008-09-1615:14:54

2008-09-1615:14:54

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Freitag, 18. Januar 2008 at 03:00: - Security Update forWindows XP (KB944653) - Security Update for Windows XP withWindows Media Format Runtime 9 (KB941569) - Update forWindows XP (KB942763) - Security Update for Windows XP(KB941644) - Update for Windows XP (KB938828) - SecurityUpdate for Windows XP (KB936021) - Update for Windows XP(KB942840) - Security Update for Windows XP (KB937894) -Security Update for Windows XP (KB943460)

79 2008-09-1615:14:46

2008-09-1615:14:47

Service Control Manager INFO 7036 2

Description The Computer Browser service entered the stopped state.80 2008-09-16

15:14:522008-09-1615:14:56

Print WARNING 4 2

Description Printer _#VMwareVirtualPrinter is pending deletion.81 2008-09-16

15:14:512008-09-1615:14:51

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 7. November 2007 at 03:00: - Security Updatefor Windows XP (KB928843) - Security Update for Flash Player(KB923789) - Update for Windows XP (KB930916) - SecurityUpdate for Windows XP (KB920213) - Security Update for WindowsXP (KB926255) - Security Update for Windows XP (KB918118) -Update for Windows XP (KB922582) - Security Update for WindowsXP (KB923191) - Security Update for Windows XP (KB932168) -Security Update for Microsoft .NET Framework, Version 2.0(KB928365) - Security Update for Windows XP (KB919007) -Security Update for Windows XP (KB930178) - Update for WindowsXP (KB920872) - Security Update for Windows XP (KB926436) -Security Update for Microsoft XML Core Services 6.0 and MicrosoftXML Core Services 6.0 Service Pack 1 (KB933579)

82 2008-09-1615:14:51

2008-09-1615:14:51

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 7. November 2007 at 03:00: - Security Updatefor Windows XP (KB928843) - Security Update for Flash Player(KB923789)

83 2008-09-1615:14:45

2008-09-1615:14:46

Service Control Manager INFO 7036 2

Description The Network Connections service entered the running state.

11/37

84 2008-09-1615:14:46

2008-09-1615:14:46

Service Control Manager INFO 7035 2

Description The Fast User Switching Compatibility service was successfully senta start control.

85 2008-09-1615:14:46

2008-09-1615:14:46

Service Control Manager INFO 7036 2

Description The Fast User Switching Compatibility service entered the runningstate.

86 2008-09-1615:14:55

2008-09-1615:14:55

NtServicePack INFO 4377 2

Description Windows XP Hotfix KB943460 was installed.87 2008-09-16

15:14:522008-09-1615:14:56

Print WARNING 3 2

Description Printer _#VMwareVirtualPrinter was deleted.88 2008-09-16

15:14:482008-09-1615:14:48

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Mittwoch, 16. August 2006 at 03:00: - Security Updatefor Windows XP (KB914389) - Security Update for Windows XP(KB920683) - Security Update for Windows XP (KB908519) -Update for Windows XP (KB894391) - Cumulative Security Updatefor Outlook Express for Windows XP (KB911567) - Security Updatefor Windows XP (KB896428) - Security Update for Windows XP(KB913580) - Security Update for Windows XP (KB905749) -Security Update for Windows XP (KB908531) - Security Update forWindows XP (KB904706) - Update for Windows XP (KB916595) -Security Update for Windows XP (KB912919) - Security Update forWindows XP (KB900725) - Security Update for Windows XP(KB888302) - Security Update for Windows XP (KB917422) -Security Update for Windows XP (KB901214) - Security Update forWindows XP (KB917953) - Security Update for Windows XP(KB905414) - Security Update for Windows XP (KB917344) -Security Update for Windows XP (KB914388) - Security Update forWindows Media Player Plug-in (KB911564) - Update for WindowsXP (KB910437) - Securi

89 2008-09-1615:14:45

2008-09-1615:14:46

Service Control Manager INFO 7035 2

Description The Network Connections service was successfully sent a startcontrol.

12/37

90 2008-09-1615:14:54

2008-09-1615:14:54

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Freitag, 18. Januar 2008 at 03:00: - Security Update forWindows XP (KB944653) - Cumulative Security Update for InternetExplorer 6 for Windows XP (KB942615) - Security Update forWindows XP (KB943485) - Security Update for Windows XP(KB941568) - Security Update for Windows XP with Windows MediaFormat Runtime 9 (KB941569) - Update for Windows XP(KB942763) - Security Update for Windows XP (KB941644) -Update for Windows XP (KB938828) - Security Update for WindowsXP (KB936021) - Update for Windows XP (KB942840) - SecurityUpdate for Windows XP (KB937894) - Security Update for WindowsXP (KB943460)

91 2008-09-1615:14:41

2008-09-1615:14:42

LoadPerf INFO 1000 2

Description Performance counters for the ISAPISearch (ISAPISearch) servicewere loaded successfully. The Record Data contains the new indexvalues assigned to this service.

92 2008-09-1615:14:41

2008-09-1615:14:42

LoadPerf INFO 1000 2

Description Performance counters for the ContentFilter (ContentFilter) servicewere loaded successfully. The Record Data contains the new indexvalues assigned to this service.

93 2008-09-1615:14:56

2008-09-1615:14:56

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Dienstag, 16. September 2008 at 03:00: - SecurityUpdate for Windows XP (KB938464)

94 2008-09-1615:14:41

2008-09-1615:14:42

LoadPerf INFO 1000 2

Description Performance counters for the ContentIndex (ContentIndex) servicewere loaded successfully. The Record Data contains the new indexvalues assigned to this service.

95 2008-09-1615:14:56

2008-09-1615:14:56

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Dienstag, 16. September 2008 at 03:00: - SecurityUpdate for Windows XP (KB938464) - Security Update for OutlookExpress for Windows XP (KB951066) - Update for Windows XP(KB952287) - Security Update for Windows XP (KB950762)

13/37

96 2008-09-1615:14:42

2008-09-1615:14:42

WinMgmt WARNING 5603 2

Description A provider, Rsop Planning Mode Provider, has been registered inthe WMI namespace, root\RSOP, but did not specify theHostingModel property. This provider will be run using theLocalSystem account. This account is privileged and the providermay cause a security violation if it does not correctly impersonateuser requests. Ensure that provider has been reviewed for securitybehavior and update the HostingModel property of the providerregistration to an account with the least privileges possible for therequired functionality.

97 2008-09-1615:14:41

2008-09-1615:14:42

EAPOL INFO 2001 2

Description EAPOL service was started successfully98 2008-09-16

15:14:422008-09-1615:14:42

MsiInstaller INFO 11728 2

Description Product: WebFldrs XP -- Configuration completed successfully.99 2008-09-16

15:14:422008-09-1615:14:45

Userenv WARNING 1517 2

Description Windows saved user XPTEST\Administrator registry while anapplication or service was still using the registry during log off. Thememory used by the user's registry has not been freed. The registrywill be unloaded when it is no longer in use. This is often caused byservices running as a user account, try configuring the services torun in either the LocalService or NetworkService account.

100 2008-09-1615:14:56

2008-09-1615:14:56

Windows Update Agent INFO 18 2

Description Installation Ready: The following updates are downloaded and readyfor installation. This computer is currently scheduled to install theseupdates on Montag, 15. September 2008 at 17:24: - CumulativeSecurity Update for Internet Explorer 7 for Windows XP (KB944533)- Security Update for Windows XP (KB946026)

101 - - All other events NOTICE - 477Description All other events

MACHINENAME

No. First Event Last Event Process TypeEventID

Count

1 2008-09-1615:21:09

2008-09-1615:21:09

ESENT NOTICE 100 3

Description svchost (648) The database engine 5.02.3790.1830 started.2 2008-09-16

15:21:092008-09-1615:21:09

WinMgmt WARNING 63 2

Description A provider, CmdTriggerConsumer, has been registered in the WMInamespace, Root\cimv2, to use the LocalSystem account. This account isprivileged and the provider may cause a security violation if it does notcorrectly impersonate user requests.

14/37

3 2008-09-1615:14:45

2008-09-1615:21:13

Serial INFO 2 2

Description While validating that \Device\Serial0 was really a serial port, a fifo wasdetected. The fifo will be used.

4 2008-09-1615:21:09

2008-09-1615:21:10

WinMgmt WARNING 5603 2

Description A provider, Rsop Planning Mode Provider, has been registered in the WMInamespace, root\RSOP, but did not specify the HostingModel property.This provider will be run using the LocalSystem account. This account isprivileged and the provider may cause a security violation if it does notcorrectly impersonate user requests. Ensure that provider has beenreviewed for security behavior and update the HostingModel property ofthe provider registration to an account with the least privileges possible forthe required functionality.

5 2008-09-1615:21:09

2008-09-1615:21:09

ESENT NOTICE 101 2

Description svchost (648) The database engine stopped.6 2008-09-16

15:14:452008-09-1615:21:13

Serial INFO 2 2

Description While validating that \Device\Serial1 was really a serial port, a fifo wasdetected. The fifo will be used.

7 2008-09-1615:14:45

2008-09-1615:21:13

EventLog INFO 6005 2

Description The Event log service was started.8 2008-09-16

15:21:132008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\FIXEDBUTTON\2&DABA3FF&0 Vetoing device:ACPI\FixedButton\2&daba3ff&0 Vetoing service name: Driver\ACPI Vetotype 6: PNP_VetoDevice When Windows attempts to install, upgrade,remove, or reconfigure a device, it queries the driver responsible for thatdevice to confirm that the operation can be performed. If any of thesedrivers denies permission (query-removal veto), then the computer mustbe restarted in order to complete the operation. User Action Restart yourcomputer.

15/37

9 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\PNP0A03\2&DABA3FF&0 Vetoing device:IDE\DiskVMware_Virtual_IDE_Hard_Drive___________00000001\303030303030303030303030303030303030313 0 Vetoing service name:Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts toinstall, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

10 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:PCI\VEN_8086&DEV_7110&SUBSYS_00000000&REV_08\3&61AAA01&0&38 Vetoing device:ACPI\PNP0F13\4&5289e18&0 Vetoing service name: Driver\i8042prtVeto type 6: PNP_VetoDevice When Windows attempts to install,upgrade, remove, or reconfigure a device, it queries the driver responsiblefor that device to confirm that the operation can be performed. If any ofthese drivers denies permission (query-removal veto), then the computermust be restarted in order to complete the operation. User Action Restartyour computer.

11 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:PCI\VEN_8086&DEV_7111&SUBSYS_197615AD&REV_01\3&61AAA01&0&39 Vetoing device:IDE\DiskVMware_Virtual_IDE_Hard_Drive___________00000001\303030303030303030303030303030303030313 0 Vetoing service name:Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts toinstall, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

16/37

12 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:PCIIDE\IDECHANNEL\4&23686003&0&0 Vetoing device:IDE\DiskVMware_Virtual_IDE_Hard_Drive___________00000001\303030303030303030303030303030303030313 0 Vetoing service name:Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts toinstall, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

13 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\PNP0303\4&5289E18&0 Vetoing device:ACPI\PNP0303\4&5289e18&0 Vetoing service name: Driver\i8042prt Vetotype 6: PNP_VetoDevice When Windows attempts to install, upgrade,remove, or reconfigure a device, it queries the driver responsible for thatdevice to confirm that the operation can be performed. If any of thesedrivers denies permission (query-removal veto), then the computer mustbe restarted in order to complete the operation. User Action Restart yourcomputer.

14 2008-09-1615:21:13

2008-09-1615:21:13

Workstation NOTICE 3261 1

Description This computer has been successfully joined to workgroup 'VMWARE'.15 2008-09-16

15:21:132008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:IDE\DISKVMWARE_VIRTUAL_IDE_HARD_DRIVE___________00000001\303030303030303030303030303030303030313 0 Vetoing device:IDE\DiskVMware_Virtual_IDE_Hard_Drive___________00000001\303030303030303030303030303030303030313 0 Vetoing service name:Driver\Disk Veto type 6: PNP_VetoDevice When Windows attempts toinstall, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

17/37

16 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:STORAGE\VOLUME\1&30A96598&0&SIGNATUREAC0EAC0EOFFSET7E00LENGTH3FF 2E5000 Vetoing device:STORAGE\Volume\1&30a96598&0&SignatureAC0EAC0EOffset7E00Length3FF 2E5000 Vetoing service name:FileSystem\Ntfs Veto type 6: PNP_VetoDevice When Windows attemptsto install, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

17 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\PNP0B00\4&5289E18&0 Vetoing device:ACPI\PNP0B00\4&5289e18&0 Vetoing service name: Driver\ACPI Vetotype 6: PNP_VetoDevice When Windows attempts to install, upgrade,remove, or reconfigure a device, it queries the driver responsible for thatdevice to confirm that the operation can be performed. If any of thesedrivers denies permission (query-removal veto), then the computer mustbe restarted in order to complete the operation. User Action Restart yourcomputer.

18 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\PNP0F13\4&5289E18&0 Vetoing device:ACPI\PNP0F13\4&5289e18&0 Vetoing service name: Driver\i8042prtVeto type 6: PNP_VetoDevice When Windows attempts to install,upgrade, remove, or reconfigure a device, it queries the driver responsiblefor that device to confirm that the operation can be performed. If any ofthese drivers denies permission (query-removal veto), then the computermust be restarted in order to complete the operation. User Action Restartyour computer.

19 2008-09-1615:21:11

2008-09-1615:21:11

Security NOTICE 576 1

Description Special privileges assigned to new logon: User Name: NETWORKSERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges:SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege

18/37

20 2008-09-1615:21:11

2008-09-1615:21:11

Security NOTICE 612 1

Description Audit Policy Change: New Policy: Success Failure + - Logon/Logoff - -Object Access - - Privilege Use - - Account Management - - PolicyChange - - System - - Detailed Tracking - - Directory Service Access + -Account Logon Changed By: User Name: MACHINENAME$ DomainName: Logon ID: (0x0,0x3E7)

21 2008-09-1615:21:09

2008-09-1615:21:09

EventSystem NOTICE 4625 1

Description The EventSystem sub system is suppressing duplicate event log entriesfor a duration of 86400 seconds. The suppression timeout can becontrolled by a REG_DWORD value named SuppressDuplicateDurationunder the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.

22 2008-09-1615:21:09

2008-09-1615:21:09

WinMgmt WARNING 63 1

Description A provider, HiPerfCooker_v1, has been registered in the WMInamespace, Root\WMI, to use the LocalSystem account. This account isprivileged and the provider may cause a security violation if it does notcorrectly impersonate user requests.

23 2008-09-1615:14:45

2008-09-1615:14:45

EventLog INFO 6009 1

Description Microsoft (R) Windows (R) 5.01. 2600 Uniprocessor Free.24 2008-09-16

15:21:112008-09-1615:21:11

Security NOTICE 528 1

Description Successful Logon: User Name: LOCAL SERVICE Domain: NTAUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process:Advapi Authentication Package: Negotiate Workstation Name: LogonGUID: - Caller User Name: MACHINENAME$ Caller Domain: CallerLogon ID: (0x0,0x3E7) Caller Process ID: 284 Transited Services: -Source Network Address: - Source Port: -

25 2008-09-1615:21:11

2008-09-1615:21:11

Security NOTICE 576 1

Description Special privileges assigned to new logon: User Name: LOCAL SERVICEDomain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges:SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege

26 2008-09-1615:21:13

2008-09-1615:21:13

DCOM NOTICE 10026 1

Description The COM sub system is suppressing duplicate event log entries for aduration of 86400 seconds. The suppression timeout can be controlled bya REG_DWORD value named SuppressDuplicateDuration under thefollowing registry key: HKLM\Software\Microsoft\Ole\Even tLog.

27 2008-09-1615:21:13

2008-09-1615:21:13

EventLog NOTICE 6009 1

Description Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Uniprocessor Free.

19/37

28 2008-09-1615:21:11

2008-09-1615:21:11

Security NOTICE 528 1

Description Successful Logon: User Name: NETWORK SERVICE Domain: NTAUTHORITY Logon ID: (0x0,0x3E4) Logon Type: 5 Logon Process:Advapi Authentication Package: Negotiate Workstation Name: LogonGUID: - Caller User Name: MACHINENAME$ Caller Domain: CallerLogon ID: (0x0,0x3E7) Caller Process ID: 284 Transited Services: -Source Network Address: - Source Port: -

29 2008-09-1615:21:13

2008-09-1615:21:13

PlugPlayManager NOTICE 271 1

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ROOT\DMIO\0000 Vetoing device: Root\dmio\0000 Vetoing servicename: Driver\dmio Veto type 6: PNP_VetoDevice When Windowsattempts to install, upgrade, remove, or reconfigure a device, it queriesthe driver responsible for that device to confirm that the operation can beperformed. If any of these drivers denies permission (query-removal veto),then the computer must be restarted in order to complete the operation.User Action Restart your computer.

W2KTESTING

No. First Event Last Event Process TypeEventID

Count

1 2008-09-1615:15:12

2008-09-1615:21:51

EventLog INFO 6005 27

Description Der Ereignisprotokolldienst wurde gestartet.2 2008-09-16

15:15:122008-09-1615:21:51

EventLog INFO 6006 25

Description Der Ereignisprotokolldienst wurde beendet.3 2008-09-16

15:15:122008-09-1615:22:51

VMTools INFO 105 20

Description The service was started.4 2008-09-16

15:15:132008-09-1615:21:51

EventLog INFO 6009 14

Description Microsoft (R) Windows 2000 (R) 5.0 2195 Service Pack 4Uniprocessor Free.

5 2008-09-1615:15:12

2008-09-1615:15:13

EventLog INFO 6009 13

Description Microsoft (R) Windows 2000 (R) 5.0 2195 Uniprocessor Free.

20/37

6 2008-09-1615:15:11

2008-09-1615:15:12

Oakley INFO 542 13

Description Die IP-Sicherheitsrichtlinie für ISAKMP/Oakley verwendet einenVerschlüsselungsalgorithmus, der aufgrund vonExportbeschränkungen für Kryptografie ungültig ist. Die vonISAKMP/Oakley verwendete 3DES-Verschlüsselung wird auf eineStandard-DES-Verschlüsselung herabgesetzt. Dies verursacht imAllgemeinen keine Probleme. ISAKMP/Oakley kann weiterhinIP-Sicherheitsparameter aushandeln und die Aushandlung mitDES-Verschlüsselung schützen. Wenden Sie sich an denNetzwerkadministrator, wenn Sie trotzdem verlangen, dass dieISAKMP/Oakley-Aushandlung durch 3DES-Verschlüsselunggeschützt werden soll.

7 2008-09-1615:15:11

2008-09-1615:15:12

VMware Tools Service INFO 105 12

Description The description for Event ID ( 105 ) in Source ( VMware Tools Service) could not be found. It contains the following insertion string(s):

8 2008-09-1615:15:11

2008-09-1615:15:12

SceCli INFO 1704 9

Description Die Sicherheitsrichtlinien in den Gruppenrichtlinienobjekten wurdenerfolgreich angewendet.

9 2008-09-1615:15:13

2008-09-1615:15:13

MRxSmb WARNING 3034 8

Description Der Redirectordienst konnte den Sicherheitskontext oder dieAbfragekontextattribute nicht initialisieren.

10 2008-09-1615:15:11

2008-09-1615:15:11

VMware INFO 105 5

Description The description for Event ID ( 105 ) in Source ( VMware ) could not befound. It contains the following insertion string(s):

11 2008-09-1615:15:12

2008-09-1615:15:12

VMTools INFO 108 5

Description The service was stopped.12 2008-09-16

15:15:112008-09-1615:15:11

Userenv ERR 1000 5

Description Der Benutzer oder der Computername kann nicht ermittelt werden.Zurückgegebener Wert (1326).

13 2008-09-1615:15:12

2008-09-1615:15:13

NETLOGON ERR 3210 5

Description Die Authentifizierung mit \\adisconint.intern.adiscon.com, einemWindows NT- oder Windows 2000-Domänen Controller für dieDomäne ADISCON, ist fehlgeschlagen.

14 2008-09-1615:15:11

2008-09-1615:15:12

VMware Tools Service INFO 108 4

Description The description for Event ID ( 108 ) in Source ( VMware Tools Service) could not be found. It contains the following insertion string(s):

21/37

15 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 4

Description Product: Visual Studio .NET Enterprise Architect - English --Installation operation completed successfully.

16 2008-09-1615:15:11

2008-09-1615:15:11

VMware Tools Service INFO 100 4

Description The description for Event ID ( 100 ) in Source ( VMware Tools Service) could not be found. It contains the following insertion string(s):VMware Tools Service

17 2008-09-1615:15:12

2008-09-1615:21:50

Adiscon EvntSLog INFO 118 3

Description EventReporter is running in trial mode. 29 days left18 2008-09-16

15:15:122008-09-1615:15:12

MsiInstaller INFO 11728 3

Description Product: VMware Tools -- Configuration completed successfully.19 2008-09-16

15:15:132008-09-1615:15:13

DnsApi INFO 11152 3

Description Der Netzwerkadapter konnte mit folgenden Einstellungen nichtregistriert werden: Adaptername :{B28A1A2E-3AF4-4BF3-A6E0-E031391 B4BD0} Hostname :w2ktesting Adapterspezifisches Domänensuffix : intern.adiscon.comDNS-Serverliste : 172.16.0.2 Server, an den Aktualisierung gesendetwurde : 172.16.0.2 IP-Adresse(n) : 172.16.172.3 Die Registrierung istaufgrund der folgenden Ursachen fehlgeschlagen: (a) DerDNS-Server unterstützt das Protokoll für die dynamischeDNS-Aktualisierung nicht. (b) Die primäre autorisierende Zone für dieNamensregistrierung lässt zurzeit keine dynamischenAktualisierungen zu. Wenden Sie sich an den DNS-Server- oderNetzwerksystemadministrator, um einen Ressourceneintrag für einenDNS-Host (A) mit dem spezifisches DNS-Namen für diesen Adapterhinzuzufügen oder zu registrieren.

20 2008-09-1615:15:11

2008-09-1615:15:11

VMware Tools Service INFO 101 3

Description The description for Event ID ( 101 ) in Source ( VMware Tools Service) could not be found. It contains the following insertion string(s):VMware Tools Service

21 2008-09-1615:15:13

2008-09-1615:15:13

w32time WARNING 11 2

Description Der NTP-Server \\adisconone.intern.adiscon.com hat nicht reagiert.22 2008-09-16

15:15:122008-09-1615:15:12

MSDTC INFO 4097 2

Description MS DTC wurde gestartet23 2008-09-16

15:15:122008-09-1615:15:12

MsiInstaller INFO 11707 2

Description Product: Visual Studio.NET Baseline - English -- Installation operationcompleted successfully.

22/37

24 2008-09-1615:15:13

2008-09-1615:15:13

Print WARNING 2 2

Description Der Drucker "_#VMwareVirtualPrinter" wurde erstellt.25 2008-09-16

15:15:122008-09-1615:15:12

MsiInstaller INFO 11707 2

Description Product: Visual Studio .NET Enterprise Architect 2003 - English --Installation operation completed successfully.

26 2008-09-1615:15:11

2008-09-1615:15:11

VMware INFO 108 2

Description The description for Event ID ( 108 ) in Source ( VMware ) could not befound. It contains the following insertion string(s):

27 2008-09-1615:15:11

2008-09-1615:15:11

VMware INFO 101 2

Description The description for Event ID ( 101 ) in Source ( VMware ) could not befound. It contains the following insertion string(s): VMware

28 2008-09-1615:15:13

2008-09-1615:15:13

Workstation ERR 3113 2

Description Initialisierung gescheitert, da der angeforderte Dienst redirector nichtgestartet werden konnte.

29 2008-09-1615:15:11

2008-09-1615:15:11

MsiInstaller INFO 1000 2

Description Product: WebFldrs -- Installation operation completed successfully.30 2008-09-16

15:15:132008-09-1615:15:13

NETLOGON ERR 5721 2

Description Die Sitzung mit dem Windows NT- oder Windows2000-Domänencontroller der Domäne ADISCON konnte nichteingerichtet werden, da auf dem Domänencontroller kein Konto fürComputer W2KTESTING besteht.

31 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 2

Description Product: VMware Tools -- Installation operation completedsuccessfully.

32 2008-09-1615:15:11

2008-09-1615:15:11

VMware INFO 100 2

Description The description for Event ID ( 100 ) in Source ( VMware ) could not befound. It contains the following insertion string(s): VMware

33 2008-09-1615:15:12

2008-09-1615:15:12

WinMgmt WARNING 62 2

Description WMI-ADAP konnte die Leistungsbibliothek ".NET CLR Networking"nicht verarbeiten, da einer der Datenblobs Klassen mit einer Größevon null gemeldet hat.

34 2008-09-1615:15:12

2008-09-1615:15:12

WinMgmt WARNING 62 2

Description WMI-ADAP konnte die Leistungsbibliothek ".NET CLR Data" nichtverarbeiten, da einer der Datenblobs Klassen mit einer Größe von nullgemeldet hat.

23/37

35 2008-09-1615:15:13

2008-09-1615:15:13

Print WARNING 20 2

Description Druckertreiber TP Output Gateway für Windows NT x86 Version-3wurde hinzugefügt oder aktualisiert. Dateien:- TPPRN.DLL,TPPrnUI.DLL, TPOG.bin, TPOG.hlp.

36 2008-09-1615:15:13

2008-09-1615:15:13

NtServicePack INFO 4381 1

Description Windows 2000 Service Pack 4 wurde installiert.37 2008-09-16

15:15:122008-09-1615:15:12

MsiInstaller INFO 1005 1

Description Windows Installer ha iniciado un reinicio del sistema para completar ocontinuar con la configuración de 'EventReporter 9.2 - Build 301'.

38 2008-09-1615:15:13

2008-09-1615:15:13

Service Control Manager ERR 7031 1

Description Der Dienst "Windows Installer" wurde unerwartet beendet. Dies istbereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werdenin 0 Millisekunden durchgeführt: Kein Vorgang.

39 2008-09-1615:15:13

2008-09-1615:15:13

Windows Installer 3.1 INFO 4377 1

Description Windows Installer, Hotfix KB893803v2 wurde installiert.40 2008-09-16

15:15:132008-09-1615:15:13

Print WARNING 3 1

Description Der Drucker "_#VMwareVirtualPrinter" wurde gelöscht.41 2008-09-16

15:15:132008-09-1615:15:13

Print WARNING 4 1

Description Das Löschen des Druckers "_#VMwareVirtualPrinter" steht noch aus.42 2008-09-16

15:15:132008-09-1615:15:13

BROWSER INFO 8033 1

Description Der Suchdienst hat eine Wahl auf dem Netzwerk"\Device\NetBT_Tcpip_{B28A1A2E-3AF4-4BF3-A6E0-E031391B4BD0}" erzwungen, da derHauptsuchdienst beendet wurde.

43 2008-09-1615:15:12

2008-09-1615:15:12

Distributed Link Tracking Client INFO 12505 1

Description C wurde eine neue Datenträgerkennung zugewiesen:{8f34e9f4-6e48-48c8-9b5c-4ca4ce9 ebded} Die Überwachungverteilter Verknüpfungen verwendet diese Kennung, umDateiverknüpfungen (z.B. Shell- und OLE-Verknüpfungen)automatisch zu reparieren, wenn diese beschädigt wurden. Wennvorher beschädigte Verknüpfungen zu Dateien auf diesemDatenträger vorhanden sind, können diese eventuell nichtautomatisch repariert werden.

44 2008-09-1615:15:13

2008-09-1615:15:13

NETLOGON ERR 3210 1

Description Die Authentifizierung mit \\adisconone.intern.adiscon.com, einemWindows NT- oder Windows 2000-Domänen Controller für dieDomäne ADISCON, ist fehlgeschlagen.

24/37

45 2008-09-1615:15:12

2008-09-1615:15:12

ASP.NET 1.1.4322.0 WARNING 1020 1

Description Updates to the IIS metabase were aborted because IIS is either notinstalled or is disabled on this machine. To configure ASP.NET to runin IIS, please install or enable IIS and re-register ASP.NET usingaspnet_regiis.exe /i.

46 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf INFO 1000 1

Description Die Leistungsindikatoren für den Dienst ".NET CLR Networking"wurden geladen. Die Daten enthalten die dem Dienst zugeordnetenneuen Indexwerte.

47 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf INFO 1000 1

Description Die Leistungsindikatoren für den Dienst ".NET CLR Data" wurdengeladen. Die Daten enthalten die dem Dienst zugeordneten neuenIndexwerte.

48 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf INFO 1000 1

Description Die Leistungsindikatoren für den Dienst ".NETFramework" wurdengeladen. Die Daten enthalten die dem Dienst zugeordneten neuenIndexwerte.

49 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Product: Microsoft .NET Framework (English) v1.0.3705 -- Installationoperation completed successfully.

50 2008-09-1615:15:12

2008-09-1615:15:12

ASP.NET 1.0.3705.0 ERR 1031 1

Description The description for Event ID ( 1031 ) in Source ( ASP.NET 1.0.3705.0) could not be found. It contains the following insertion string(s):0x80040154

51 2008-09-1615:15:12

2008-09-1615:15:12

ASP.NET 1.0.3705.0 INFO 1017 1

Description The description for Event ID ( 1017 ) in Source ( ASP.NET 1.0.3705.0) could not be found. It contains the following insertion string(s):1.0.3705.0

52 2008-09-1615:15:11

2008-09-1615:15:11

Userenv ERR 1000 1

Description Der Benutzer oder der Computername kann nicht ermittelt werden.Zurückgegebener Wert (1317).

53 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Produkt: Windows Installer -- Die Installation wurde erfolgreichabgeschlossen.

54 2008-09-1615:15:12

2008-09-1615:15:12

WinMgmt WARNING 37 1

Description WMI-ADAP konnte die folgende Leistungsbibliothek "msdtcui.DLL"aufgrund eines unbekannten Fehlers innerhalb der Bibliothek nichtladen: 0x0

25/37

55 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Product: Microsoft FrontPage Client - English -- Installation operationcompleted successfully.

56 2008-09-1615:15:12

2008-09-1615:15:12

EventSystem WARNING 4100 1

Description Das COM+-Ereignissystem konnte nicht eine Instanz des Abonnenten{6295DF2D-35EE-11D1-8707-00C04FD 93327} erstellen.CoCreateInstanceEx gab zurück HRESULT 8000401A

57 2008-09-1615:15:12

2008-09-1615:15:12

ASP.NET 1.1.4322.0 INFO 1017 1

Description Start registering ASP.NET (version 1.1.4322.0)58 2008-09-16

15:15:122008-09-1615:15:12

LoadPerf ERR 3009 1

Description Die Zeichenfolgen der Leistungsindikatoren für .NETFrameworkkonnten nicht installiert werden. Fehlercode: DWORD 0 der Daten.

59 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Product: Microsoft .NET Framework 1.1 -- Installation operationcompleted successfully.

60 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Product: Microsoft Visual J# .NET Redistributable Package 1.1 --Installation operation completed successfully.

61 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 1005 1

Description Windows Installer ha iniciado un reinicio del sistema para completar ocontinuar con la configuración de 'VMware Tools'.

62 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf ERR 3009 1

Description Die Zeichenfolgen der Leistungsindikatoren für .NET CLR Networkingkonnten nicht installiert werden. Fehlercode: DWORD 0 der Daten.

63 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf ERR 3009 1

Description Die Zeichenfolgen der Leistungsindikatoren für .NET CLR Datakonnten nicht installiert werden. Fehlercode: DWORD 0 der Daten.

64 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf INFO 1000 1

Description Die Leistungsindikatoren für den Dienst "ASP.NET_1.1.4322" wurdengeladen. Die Daten enthalten die dem Dienst zugeordneten neuenIndexwerte.

65 2008-09-1615:15:12

2008-09-1615:15:12

LoadPerf INFO 1000 1

Description Die Leistungsindikatoren für den Dienst "ASP.NET" wurden geladen.Die Daten enthalten die dem Dienst zugeordneten neuen Indexwerte.

26/37

66 2008-09-1615:15:12

2008-09-1615:15:12

ASP.NET 1.1.4322.0 INFO 1019 1

Description Finish registering ASP.NET (version 1.1.4322.0). Detailed registrationlogs can be found in C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\ASPNETSetup.log

67 2008-09-1615:15:12

2008-09-1615:15:12

MsiInstaller INFO 11707 1

Description Product: EventReporter 9.2 - Build 301 -- Installation operationcompleted successfully.

W2003R2

No. First Event Last Event Process TypeEventID

Count

1 2008-09-1615:21:14

2008-09-1615:21:21

Service Control Manager NOTICE 7040 221

Description The start type of the Background Intelligent Transfer Service service waschanged from auto start to demand start.

2 2008-09-1615:21:14

2008-09-1615:21:21

Service Control Manager NOTICE 7040 221

Description The start type of the Background Intelligent Transfer Service service waschanged from demand start to auto start.

3 2008-09-1615:21:10

2008-09-1615:21:11

VMTools NOTICE 105 14

Description The service was started.4 2008-09-16

15:21:112008-09-1615:22:27

Security NOTICE 680 10

Description Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE _V1_0Logon account: Administrator Source Workstation: W2003R2 Error Code:0x0

5 2008-09-1615:21:13

2008-09-1615:21:26

IPSec NOTICE 4295 9

Description The IPSec Driver is starting in Bypass mode. No IPSec security is beingapplied while this computer starts up. IPSec policies, if they have beenassigned, will be applied to this computer after the IPSec services start.

6 2008-09-1615:21:09

2008-09-1615:21:11

EventSystem NOTICE 4625 9

Description The EventSystem sub system is suppressing duplicate event log entriesfor a duration of 86400 seconds. The suppression timeout can becontrolled by a REG_DWORD value named SuppressDuplicateDurationunder the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.

27/37

7 2008-09-1615:21:09

2008-09-1615:21:11

MSDTC NOTICE 4193 9

Description MS DTC started with the following settings (OFF = 0 and ON = 1):Security Configuration: Network Administration of Transactions = 0,Network Clients = 0, Inbound Distributed Transactions using NativeMSDTC Protocol = 0, Outbound Distributed Transactions using NativeMSDTC Protocol = 0, Transaction Internet Protocol (TIP) = 0, XATransactions = 0 Filtering Duplicate events =

8 2008-09-1615:21:11

2008-09-1615:22:27

Security NOTICE 576 9

Description Special privileges assigned to new logon: User Name: LOCAL SERVICEDomain: NT AUTHORITY Logon ID: (0x0,0x3E5) Privileges:SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege

9 2008-09-1615:21:10

2008-09-1615:21:11

WinMgmt WARNING 5603 9

Description A provider, TPAutoConnDLL, has been registered in the WMI namespace,Root\ThinPrint, but did not specify the HostingModel property. Thisprovider will be run using the LocalSystem account. This account isprivileged and the provider may cause a security violation if it does notcorrectly impersonate user requests. Ensure that provider has beenreviewed for security behavior and update the HostingModel property ofthe provider registration to an account with the least privileges possible forthe required functionality.

10 2008-09-1615:21:11

2008-09-1615:21:13

Security NOTICE 576 8

Description Special privileges assigned to new logon: User Name: NETWORKSERVICE Domain: NT AUTHORITY Logon ID: (0x0,0x3E4) Privileges:SeAuditPrivilege SeAssignPrimaryTokenPrivilege SeImpersonatePrivilege

11 2008-09-1615:21:13

2008-09-1615:21:26

AeLookupSvc NOTICE 3 8

Description The Application Experience Lookup service started successfully.12 2008-09-16

15:21:132008-09-1615:21:26

DCOM NOTICE 10026 8

Description The COM sub system is suppressing duplicate event log entries for aduration of 86400 seconds. The suppression timeout can be controlled bya REG_DWORD value named SuppressDuplicateDuration under thefollowing registry key: HKLM\Software\Microsoft\Ole\Even tLog.

13 2008-09-1615:21:13

2008-09-1615:21:26

EventLog NOTICE 6009 8

Description Microsoft (R) Windows (R) 5.02. 3790 Service Pack 1 Uniprocessor Free.14 2008-09-16

15:21:112008-09-1615:21:13

Security NOTICE 528 8

Description Successful Logon: User Name: SYSTEM Domain: NT AUTHORITYLogon ID: (0x0,0x3E7) Logon Type: 0 Logon Process: - AuthenticationPackage: - Workstation Name: - Logon GUID: - Caller User Name: -Caller Domain: - Caller Logon ID: - Caller Process ID: 4 TransitedServices: - Source Network Address: - Source Port: -

28/37

15 2008-09-1615:21:13

2008-09-1615:21:26

IPSec NOTICE 4294 8

Description The IPSec driver has entered Secure mode. IPSec policies, if they havebeen configured, are now being applied to this computer.

16 2008-09-1615:21:13

2008-09-1615:21:26

EventLog NOTICE 6005 8

Description The Event log service was started.17 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7035 8

Description The Network Location Awareness (NLA) service was successfully sent astart control.

18 2008-09-1615:21:09

2008-09-1615:23:27

LoadPerf NOTICE 1000 8

Description Performance counters for the WmiApRpl (WmiApRpl) service were loadedsuccessfully. The Record Data contains the new index values assigned tothis service.

19 2008-09-1615:21:24

2008-09-1615:21:26

Print NOTICE 9 8

Description Printer _#VMwareVirtualPrinter was set.20 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7036 8

Description The Network Location Awareness (NLA) service entered the runningstate.

21 2008-09-1615:21:14

2008-09-1615:21:26

Service Control Manager NOTICE 7035 8

Description The Terminal Services service was successfully sent a start control.22 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7036 8

Description The Terminal Services service entered the running state.23 2008-09-16

15:21:092008-09-1615:23:27

LoadPerf NOTICE 1001 7

Description Performance counters for the WmiApRpl (WmiApRpl) service wereremoved successfully. The Record Data contains the new values of thesystem Last Counter and Last Help registry entries.

24 2008-09-1615:21:13

2008-09-1615:21:26

EventLog NOTICE 6006 7

Description The Event log service was stopped.25 2008-09-16

15:21:112008-09-1615:21:13

SECURITY NOTICE 513 7

Description Windows is shutting down. All logon sessions will be terminated by thisshutdown.

26 2008-09-1615:21:24

2008-09-1615:21:26

Service Control Manager NOTICE 7036 6

Description The Network Connections service entered the running state.27 2008-09-16

15:21:242008-09-1615:21:26

Service Control Manager NOTICE 7035 6

Description The Network Connections service was successfully sent a start control.

29/37

28 2008-09-1615:21:10

2008-09-1615:21:11

VMTools NOTICE 108 5

Description The service was stopped.29 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7035 5

Description The Windows Installer service was successfully sent a start control.30 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7036 5

Description The Windows Installer service entered the running state.31 2008-09-16

15:21:142008-09-1615:30:27

Service Control Manager NOTICE 7036 5

Description The Windows Installer service entered the stopped state.32 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7036 4

Description The VMware Tools Service service entered the running state.33 2008-09-16

15:21:142008-09-1615:21:26

Service Control Manager NOTICE 7040 4

Description The start type of the vmx_svga service was changed from system start todemand start.

34 2008-09-1615:21:14

2008-09-1615:21:26

Service Control Manager NOTICE 7035 4

Description The VMware Tools Service service was successfully sent a start control.35 2008-09-16

15:21:102008-09-1615:21:11

MsiInstaller NOTICE 1005 4

Description The Windows Installer initiated a system restart to complete or continuethe configuration of 'VMware Tools'.

36 2008-09-1615:21:14

2008-09-1615:21:26

PlugPlayManager NOTICE 271 4

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:ACPI\PNP0F13\4&5289E18&0 Vetoing device:ACPI\PNP0F13\4&5289e18&0 Vetoing service name: Driver\i8042prtVeto type 6: PNP_VetoDevice When Windows attempts to install,upgrade, remove, or reconfigure a device, it queries the driver responsiblefor that device to confirm that the operation can be performed. If any ofthese drivers denies permission (query-removal veto), then the computermust be restarted in order to complete the operation. User Action Restartyour computer.

37 2008-09-1615:21:24

2008-09-1615:21:26

Service Control Manager NOTICE 7040 3

Description The start type of the vmx_svga service was changed from demand start tosystem start.

30/37

38 2008-09-1615:21:24

2008-09-1615:21:26

PlugPlayManager NOTICE 271 3

Description The Plug and Play operation cannot be completed because a devicedriver is preventing the device from stopping. The name of the devicedriver is listed as the vetoing service name below. Vetoed device:PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&61AAA01&0&78 Vetoing device:PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&61aaa01&0&78 Vetoing service name:Driver\vmx_svga Veto type 6: PNP_VetoDevice When Windows attemptsto install, upgrade, remove, or reconfigure a device, it queries the driverresponsible for that device to confirm that the operation can be performed.If any of these drivers denies permission (query-removal veto), then thecomputer must be restarted in order to complete the operation. UserAction Restart your computer.

39 2008-09-1615:21:24

2008-09-1615:21:26

Service Control Manager NOTICE 7036 3

Description The VMware Tools Service service entered the stopped state.40 2008-09-16

15:21:242008-09-1615:21:26

Print WARNING 20 3

Description Printer Driver TP Output Gateway for Windows NT x86 Version-3 wasadded or updated. Files:- TPPRN.DLL, TPPrnUI.DLL, TPOG.bin,TPOG.hlp.

41 2008-09-1615:21:11

2008-09-1615:21:11

Adiscon EvntSLog NOTICE 118 3

Description EventReporter is running in trial mode. 29 days left42 2008-09-16

15:21:242008-09-1615:21:26

Print NOTICE 2 3

Description Printer _#VMwareVirtualPrinter was created.43 2008-09-16

15:21:242008-09-1615:21:26

Service Control Manager NOTICE 7035 3

Description The VMware Tools Service service was successfully sent a stop control.44 2008-09-16

15:21:102008-09-1615:21:11

crypt32 NOTICE 2 3

Description Successful auto update retrieval of third-party root list cab from: 45 2008-09-16

15:21:262008-09-1615:21:26

Service Control Manager NOTICE 7036 3

Description The Adiscon EvntSLog service entered the running state.46 2008-09-16

15:21:102008-09-1615:21:11

crypt32 NOTICE 7 3

Description Successful auto update retrieval of third-party root list sequence numberfrom:

47 2008-09-1615:21:10

2008-09-1615:21:11

MsiInstaller NOTICE 11728 3

Description Product: VMware Tools -- Configuration completed successfully.48 2008-09-16

15:21:262008-09-1615:21:26

Service Control Manager NOTICE 7035 3

Description The Adiscon EvntSLog service was successfully sent a start control.

31/37

49 2008-09-1615:21:12

2008-09-1615:21:12

Security NOTICE 552 2

Description Logon attempt using explicit credentials: Logged on user: User Name:W2003R2$ Domain: VMWARE Logon ID: (0x0,0x3E7) Logon GUID: -User whose credentials were used: Target User Name: AdministratorTarget Domain: W2003R2 Target Logon GUID: - Target Server Name:localhost Target Server Info: localhost Caller Process ID: 568 SourceNetwork Address: 127.0.0.1 Source Port: 0

50 2008-09-1615:21:13

2008-09-1615:22:27

Security NOTICE 528 2

Description Successful Logon: User Name: Administrator Domain: W2003R2 LogonID: (0x0,0xE4C7) Logon Type: 2 Logon Process: User32 AuthenticationPackage: Negotiate Workstation Name: W2003R2 Logon GUID: - CallerUser Name: W2003R2$ Caller Domain: VMWARE Caller Logon ID:(0x0,0x3E7) Caller Process ID: 640 Transited Services: - Source NetworkAddress: 127.0.0.1 Source Port: 0

51 2008-09-1615:21:13

2008-09-1615:22:27

Security NOTICE 552 2

Description Logon attempt using explicit credentials: Logged on user: User Name:W2003R2$ Domain: VMWARE Logon ID: (0x0,0x3E7) Logon GUID: -User whose credentials were used: Target User Name: AdministratorTarget Domain: W2003R2 Target Logon GUID: - Target Server Name:localhost Target Server Info: localhost Caller Process ID: 640 SourceNetwork Address: 127.0.0.1 Source Port: 0

52 2008-09-1615:21:13

2008-09-1615:22:26

Security NOTICE 528 2

Description Successful Logon: User Name: LOCAL SERVICE Domain: NTAUTHORITY Logon ID: (0x0,0x3E5) Logon Type: 5 Logon Process:Advapi Authentication Package: Negotiate Workstation Name: LogonGUID: - Caller User Name: W2003R2$ Caller Domain: VMWARE CallerLogon ID: (0x0,0x3E7) Caller Process ID: 684 Transited Services: -Source Network Address: - Source Port: -

53 2008-09-1615:21:14

2008-09-1615:21:14

Service Control Manager NOTICE 7035 2

Description The Application Layer Gateway Service service was successfully sent astart control.

54 2008-09-1615:21:26

2008-09-1615:21:26

Service Control Manager NOTICE 7035 2

Description The Adiscon EvntSLog service was successfully sent a stop control.55 2008-09-16

15:21:262008-09-1615:21:26

Service Control Manager NOTICE 7036 2

Description The Adiscon EvntSLog service entered the stopped state.

32/37

56 2008-09-1615:21:12

2008-09-1615:21:12

Security NOTICE 552 2

Description Logon attempt using explicit credentials: Logged on user: User Name:W2003R2$ Domain: VMWARE Logon ID: (0x0,0x3E7) Logon GUID: -User whose credentials were used: Target User Name: AdministratorTarget Domain: W2003R2 Target Logon GUID: - Target Server Name:localhost Target Server Info: localhost Caller Process ID: 532 SourceNetwork Address: 127.0.0.1 Source Port: 0

57 2008-09-1615:21:14

2008-09-1615:21:14

Service Control Manager NOTICE 7036 2

Description The Computer Browser service entered the stopped state.58 2008-09-16

15:21:142008-09-1615:21:14

Service Control Manager NOTICE 7036 2

Description The Application Layer Gateway Service service entered the running state.59 2008-09-16

15:21:122008-09-1615:21:13

Security NOTICE 552 2

Description Logon attempt using explicit credentials: Logged on user: User Name:W2003R2$ Domain: VMWARE Logon ID: (0x0,0x3E7) Logon GUID: -User whose credentials were used: Target User Name: AdministratorTarget Domain: W2003R2 Target Logon GUID: - Target Server Name:localhost Target Server Info: localhost Caller Process ID: 712 SourceNetwork Address: 127.0.0.1 Source Port: 0

60 2008-09-1615:21:13

2008-09-1615:22:27

Security NOTICE 540 2

Description Successful Network Logon: User Name: Domain: Logon ID: (0x0,0xA635)Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLMWorkstation Name: Logon GUID: - Caller User Name: - Caller Domain: -Caller Logon ID: - Caller Process ID: - Transited Services: - SourceNetwork Address: - Source Port: -

61 2008-09-1615:21:25

2008-09-1615:21:26

Print WARNING 4 2

Description Printer _#VMwareVirtualPrinter is pending deletion.62 2008-09-16

15:21:252008-09-1615:21:26

W32Time NOTICE 37 2

Description The time provider NtpClient is currently receiving valid time data fromtime.windows.com (ntp.m|0x1|172.16.0.124:123->207 .46.197.32:123).

63 2008-09-1615:21:11

2008-09-1615:21:11

Adiscon EvntSLog ERR 1005 2

Description Can't initiate the SETP session. This error Event will NOT be loggedagain. If the connection is restored, the Event 1012 will be logged. Mostprobably the SETP server could not be reached or does not answer.Please check the the configuration holds the correct server name or IPaddress as well as the correct port. If you use an server name, you mightwant to check the dns settings to make sure the name can be resolved.Please also check if the SETP server process is operational. AdditionalInformation: Couldn't connect to host Additional help might be available athttp://www.adiscon.com/EventHelp .asp

33/37

64 2008-09-1615:21:10

2008-09-1615:21:10

PassportManager NOTICE 5008 2

Description Passport Manager configuration ok.65 2008-09-16

15:21:252008-09-1615:21:26

W32Time NOTICE 35 2

Description The time service is now synchronizing the system time with the timesource time.windows.com (ntp.m|0x1|172.16.0.124:123->207.46.197.32:123).

66 2008-09-1615:21:11

2008-09-1615:21:12

Security NOTICE 552 2

Description Logon attempt using explicit credentials: Logged on user: User Name:W2003R2$ Domain: VMWARE Logon ID: (0x0,0x3E7) Logon GUID: -User whose credentials were used: Target User Name: AdministratorTarget Domain: W2003R2 Target Logon GUID: - Target Server Name:localhost Target Server Info: localhost Caller Process ID: 572 SourceNetwork Address: 127.0.0.1 Source Port: 0

67 2008-09-1615:21:25

2008-09-1615:21:26

Print WARNING 3 2

Description Printer _#VMwareVirtualPrinter was deleted.68 2008-09-16

15:21:112008-09-1615:21:11

Userenv WARNING 1517 2

Description Windows saved user W2003R2\Administrator registry while an applicationor service was still using the registry during log off. The memory used bythe user's registry has not been freed. The registry will be unloaded whenit is no longer in use. This is often caused by services running as a useraccount, try configuring the services to run in either the LocalService orNetworkService account.

69 2008-09-1615:21:13

2008-09-1615:22:27

Security NOTICE 576 2

Description Special privileges assigned to new logon: User Name: AdministratorDomain: W2003R2 Logon ID: (0x0,0xE4C7) Privileges:SeSecurityPrivilege SeBackupPrivilege SeRestorePrivilegeSeTakeOwnershipPrivilege SeDebugPrivilegeSeSystemEnvironmentPrivilege SeLoadDriverPrivilegeSeImpersonatePrivilege

70 2008-09-1615:21:23

2008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB911562)

71 2008-09-1615:21:23

2008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Cumulative Security Update for Outlook Express for WindowsServer 2003 (KB911567)

72 2008-09-1615:21:23

2008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB911280 was installed.

34/37

73 2008-09-1615:21:23

2008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB918439)

74 2008-09-1615:21:23

2008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB917953)

75 2008-09-1615:21:23

2008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB911562 was installed.76 2008-09-16

15:21:232008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB908531)

77 2008-09-1615:21:23

2008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB914389)

78 2008-09-1615:21:23

2008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB917344 was installed.79 2008-09-16

15:21:232008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB917344)

80 2008-09-1615:21:23

2008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB917953 was installed.81 2008-09-16

15:21:232008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB914389 was installed.82 2008-09-16

15:21:232008-09-1615:21:23

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB917734)

83 2008-09-1615:21:23

2008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB918439 was installed.84 2008-09-16

15:21:232008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB911567 was installed.85 2008-09-16

15:21:232008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB917734 was installed.86 2008-09-16

15:21:232008-09-1615:21:23

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB908531 was installed.

35/37

87 2008-09-1615:21:22

2008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB896424 was installed.88 2008-09-16

15:21:222008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB902400 was installed.89 2008-09-16

15:21:222008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB905414)

90 2008-09-1615:21:22

2008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB902400)

91 2008-09-1615:21:22

2008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB899589 was installed.92 2008-09-16

15:21:222008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB901017 was installed.93 2008-09-16

15:21:222008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB899589)

94 2008-09-1615:21:22

2008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB905414 was installed.95 2008-09-16

15:21:222008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB899591)

96 2008-09-1615:21:22

2008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB899587)

97 2008-09-1615:21:22

2008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB899587 was installed.98 2008-09-16

15:21:222008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB890046 was installed.99 2008-09-16

15:21:222008-09-1615:21:22

Windows Update Agent NOTICE 19 1

Description Installation Successful: Windows successfully installed the followingupdate: Security Update for Windows Server 2003 (KB890046)

100 2008-09-1615:21:22

2008-09-1615:21:22

NtServicePack NOTICE 4377 1

Description Windows Server 2003 Hotfix KB899591 was installed.

36/37

101 - - All other events NOTICE - 183Description All other events

Made by Adiscon GmbH (2009) Report Version 1 Partners: Rsyslog | WinSyslog Report rendered in: 0.39s, 1.23s, 1.23s 2.54s 2.54s 2.55s 2.55s 2.56s 2.56s | DB queries: 10

37/37