Event[0]: Log Name: System Source: EventLog Date: 2015-08-22T04:09:56.000 Event ID: 6011 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The NetBIOS name and DNS host name of this machine have been changed from DESKTOP-QGL8DMR to SURVEILLANCE1. Event[1]: Log Name: System Source: EventLog Date: 2015-08-22T04:09:56.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[2]: Log Name: System Source: EventLog Date: 2015-08-22T04:09:56.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[3]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-07-10T05:57:52.125 Event ID: 109 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The kernel power manager has initiated a shutdown transition. Shutdown Reason: Kernel API Event[4]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-07-10T05:57:52.401 Event ID: 13 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The operating system is shutting down at system time ?2015?-?07?-?10T09:57:52.401909100Z. Event[5]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:07:42.760 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?22T08:07:42.494282300Z. Event[6]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:07:42.760 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was true. The last boot's success status was true. Event[7]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:07:42.760 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[8]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:07:42.760 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[9]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:07:42.760 Event ID: 26 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A one-time boot sequence was used during this boot. Event[10]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:07:42.760 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[11]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:07:44.324 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[12]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:07:44.324 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[13]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-22T04:07:46.727 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[14]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:08:10.526 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[15]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:08:11.250 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[16]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:08:11.252 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[17]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:08:11.253 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[18]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:08:11.254 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[19]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:08:11.997 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[20]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-22T04:08:12.360 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[21]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:13.715 Event ID: 15 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Hive \SystemRoot\System32\config\DRIVERS was reorganized with a starting size of 5046272 bytes and an ending size of 5095424 bytes. Event[22]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:14.279 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \SystemRoot\System32\Config\SOFTWARE was cleared updating 59799 keys and creating 6488 modified pages. Event[23]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:14.842 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \SystemRoot\System32\Config\DEFAULT was cleared updating 3 keys and creating 1 modified pages. Event[24]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:15.195 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \SystemRoot\System32\Config\SECURITY was cleared updating 3 keys and creating 2 modified pages. Event[25]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:15.258 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \SystemRoot\System32\Config\SAM was cleared updating 0 keys and creating 0 modified pages. Event[26]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:19.353 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT was cleared updating 598 keys and creating 33 modified pages. Event[27]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:20.097 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT was cleared updating 551 keys and creating 31 modified pages. Event[28]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:08:20.363 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Default\NTUSER.DAT was cleared updating 23 keys and creating 9 modified pages. Event[29]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:09:36.557 Event ID: 7022 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network Setup Service service hung on starting. Event[30]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:09:36.698 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the WLAN AutoConfig service was changed from demand start to auto start. Event[31]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-22T04:09:39.967 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[32]: Log Name: System Source: Microsoft-Windows-SetupPlatform Date: 2015-08-22T04:09:50.042 Event ID: 2005 Task: Install Windows Task Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: New Setup information Event[33]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:09:56.117 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \SystemRoot\System32\Config\BBI was cleared updating 3 keys and creating 1 modified pages. Event[34]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:09:56.161 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[35]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:09:56.204 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[36]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-22T04:09:58.303 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[37]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-22T04:09:58.374 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[38]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:09:59.230 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[39]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:00.170 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Defender Network Inspection System Driver service depends on the Windows Defender Mini-Filter Driver service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[40]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-22T04:10:03.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[41]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:02.952 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The IP Helper service terminated with the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[42]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:04.121 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: CSC dam Event[43]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:09.747 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Intel(R) Management Engine Interface Service File Name: \SystemRoot\System32\drivers\HECI.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[44]: Log Name: System Source: HECI Date: 2015-08-22T04:10:12.231 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[45]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:12.237 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver heci.inf_x86_5357ab4065c59b94\heci.inf for Device Instance ID PCI\VEN_8086&DEV_3B64&SUBSYS_04411028&REV_06\3&11583659&0&B0 with the following status: 0x0. Event[46]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:12.262 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Service File Name: \SystemRoot\System32\drivers\vpnva-6.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[47]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:12.327 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver vpnva-6.inf_x86_f4ee011be27e2804\vpnva-6.inf for Device Instance ID ROOT\NET\0000 with the following status: 0x0. Event[48]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:23.185 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: igfx Service File Name: \SystemRoot\system32\DRIVERS\igdkmd32.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[49]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:24.178 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service igfx for Device Instance ID PCI\VEN_8086&DEV_0046&SUBSYS_04411028&REV_18\3&11583659&0&10 with the following status: 0. Event[50]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:24.581 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver igdlh.inf_x86_a2d89ffa2b62de6a\igdlh.inf for Device Instance ID PCI\VEN_8086&DEV_0046&SUBSYS_04411028&REV_18\3&11583659&0&10 with the following status: 0x0. Event[51]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:24.981 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Realtek RT640 NT Driver Service File Name: \SystemRoot\System32\drivers\rt640x86.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[52]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:25.224 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver rt640x86.inf_x86_6211101047a3cbba\rt640x86.inf for Device Instance ID PCI\VEN_10EC&DEV_8168&SUBSYS_04411028&REV_03\4&22A5284D&0&00E2 with the following status: 0x0. Event[53]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:25.263 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Impcd Service File Name: \SystemRoot\System32\drivers\Impcd.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[54]: Log Name: System Source: rt640x86 Date: 2015-08-22T04:10:25.388 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[55]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:25.469 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver impcd.inf_x86_29638e581bcd7a99\impcd.inf for Device Instance ID PCI\VEN_8086&DEV_3B32&SUBSYS_04411028&REV_06\3&11583659&0&FE with the following status: 0x0. Event[56]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:27.032 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Intel(R) Display Audio Service File Name: \SystemRoot\system32\DRIVERS\IntcDAud.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[57]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:27.041 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service IntcDAud for Device Instance ID HDAUDIO\FUNC_01&VEN_8086&DEV_2804&SUBSYS_80860101&REV_1000\4&3742C6D0&0&0301 with the following status: 0. Event[58]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:27.866 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver intcdaud.inf_x86_717caa1600e8b146\intcdaud.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_8086&DEV_2804&SUBSYS_80860101&REV_1000\4&3742C6D0&0&0301 with the following status: 0x0. Event[59]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:28.188 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Broadcom 802.11 Network Adapter Driver Service File Name: \SystemRoot\system32\DRIVERS\bcmwl63.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[60]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:28.193 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service BCM43XX for Device Instance ID PCI\VEN_14E4&DEV_4353&SUBSYS_000E1028&REV_01\4&288D021A&0&00E1 with the following status: 0. Event[61]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:28.196 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service vwifibus for Device Instance ID PCI\VEN_14E4&DEV_4353&SUBSYS_000E1028&REV_01\4&288D021A&0&00E1 with the following status: 0. Event[62]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:28.483 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver netbc64.inf_x86_fe30979ebd99036d\netbc64.inf for Device Instance ID PCI\VEN_14E4&DEV_4353&SUBSYS_000E1028&REV_01\4&288D021A&0&00E1 with the following status: 0x0. Event[63]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:32.782 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: IDT High Definition Audio CODEC Service File Name: \SystemRoot\system32\DRIVERS\stwrt.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[64]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:32.787 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service STHDA for Device Instance ID HDAUDIO\FUNC_01&VEN_111D&DEV_7605&SUBSYS_10280441&REV_1001\4&3742C6D0&0&0001 with the following status: 0. Event[65]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:33.751 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Andrea ST Filters Service Service File Name: C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_41f81f5ce017c35c\aestsrv.exe Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[66]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:33.923 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Audio Service Service File Name: C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_41f81f5ce017c35c\STacSV.exe Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[67]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:34.145 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver stwrt.inf_x86_41f81f5ce017c35c\stwrt.inf for Device Instance ID HDAUDIO\FUNC_01&VEN_111D&DEV_7605&SUBSYS_10280441&REV_1001\4&3742C6D0&0&0001 with the following status: 0x0. Event[68]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:35.548 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: USB Video Device (WDM) Service File Name: \SystemRoot\System32\Drivers\usbvideo.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[69]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:35.557 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service usbvideo for Device Instance ID USB\VID_0C45&PID_6450&MI_00\7&2C40323E&0&0000 with the following status: 0. Event[70]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:35.813 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver usbvideo.inf_x86_fe8d886bc5539514\usbvideo.inf for Device Instance ID USB\VID_0C45&PID_6450&MI_00\7&2C40323E&0&0000 with the following status: 0x0. Event[71]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:35.869 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Streaming Clock Proxy Service File Name: \SystemRoot\system32\drivers\MSPCLOCK.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[72]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:35.875 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service MSPCLOCK for Device Instance ID SW\{97EBAACC-95BD-11D0-A3EA-00A0C9223196}\{53172480-4791-11D0-A5D6-28DB04C10000} with the following status: 0. Event[73]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.042 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver ksfilter.inf_x86_e278b8cf1c149824\ksfilter.inf for Device Instance ID SW\{97EBAACC-95BD-11D0-A3EA-00A0C9223196}\{53172480-4791-11D0-A5D6-28DB04C10000} with the following status: 0x0. Event[74]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:36.072 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Streaming Quality Manager Proxy Service File Name: \SystemRoot\system32\drivers\MSPQM.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[75]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.082 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service MSPQM for Device Instance ID SW\{DDF4358E-BB2C-11D0-A42F-00A0C9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196} with the following status: 0. Event[76]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.154 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver ksfilter.inf_x86_e278b8cf1c149824\ksfilter.inf for Device Instance ID SW\{DDF4358E-BB2C-11D0-A42F-00A0C9223196}\{97EBAACB-95BD-11D0-A3EA-00A0C9223196} with the following status: 0x0. Event[77]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:36.181 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Streaming Service Proxy Service File Name: \SystemRoot\system32\drivers\MSKSSRV.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[78]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.183 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service MSKSSRV for Device Instance ID SW\{96E080C7-143C-11D1-B40F-00A0C9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196} with the following status: 0. Event[79]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.315 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver ksfilter.inf_x86_e278b8cf1c149824\ksfilter.inf for Device Instance ID SW\{96E080C7-143C-11D1-B40F-00A0C9223196}\{3C0D501A-140B-11D1-B40F-00A0C9223196} with the following status: 0x0. Event[80]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:36.431 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Streaming Tee/Sink-to-Sink Converter Service File Name: \SystemRoot\system32\drivers\MSTEE.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[81]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.437 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service MSTEE for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196} with the following status: 0. Event[82]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.585 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver ksfilter.inf_x86_e278b8cf1c149824\ksfilter.inf for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{CF1DDA2C-9743-11D0-A3EE-00A0C9223196} with the following status: 0x0. Event[83]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.614 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service MSTEE for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000} with the following status: 0. Event[84]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.656 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver ksfilter.inf_x86_e278b8cf1c149824\ksfilter.inf for Device Instance ID SW\{CFD669F1-9BC2-11D0-8299-0000F822FE8A}\{0A4252A0-7E70-11D0-A5D6-28DB04C10000} with the following status: 0x0. Event[85]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:36.712 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Trusted Audio Drivers Service File Name: \SystemRoot\system32\drivers\drmkaud.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[86]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.722 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service drmkaud for Device Instance ID SW\{EEC12DB6-AD9C-4168-8658-B03DAEF417FE}\{ABD61E00-9350-47E2-A632-4438B90C6641} with the following status: 0. Event[87]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.773 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver wdmaudio.inf_x86_91042fc2cbb4a15c\wdmaudio.inf for Device Instance ID SW\{EEC12DB6-AD9C-4168-8658-B03DAEF417FE}\{ABD61E00-9350-47E2-A632-4438B90C6641} with the following status: 0x0. Event[88]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:10:36.880 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Virtual WiFi Miniport Service Service File Name: \SystemRoot\System32\drivers\vwifimp.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[89]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:10:36.924 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver netvwifimp.inf_x86_a371f248b1e252d2\netvwifimp.inf for Device Instance ID {5D624F94-8850-40C3-A3FA-A4FD2080BAF3}\VWIFIMP_WFD\5&280C29D8&0&01 with the following status: 0x0. Event[90]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:11:57.731 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Event[91]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:11:59.044 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout. Event[92]: Log Name: System Source: Microsoft-Windows-Bits-Client Date: 2015-08-22T04:11:59.163 Event ID: 16392 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The BITS service failed to start. Error 0x80080005. Event[93]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:11:59.153 Event ID: 7024 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Background Intelligent Transfer Service service terminated with the following service-specific error: Server execution failed Event[94]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:00.028 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[95]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:04.341 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Printer Extensions and Notifications Service File Name: %SystemRoot%\system32\svchost.exe -k print Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[96]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:04.341 Event ID: 7030 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Printer Extensions and Notifications service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Event[97]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:12:14.399 Event ID: 15 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Hive \??\C:\WINDOWS\System32\config\COMPONENTS was reorganized with a starting size of 27643904 bytes and an ending size of 27656192 bytes. Event[98]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:16.201 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Message Queuing service was changed from demand start to auto start. Event[99]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:26.186 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Net.Tcp Port Sharing Service service was changed from disabled to demand start. Event[100]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:26.186 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Net.Tcp Listener Adapter service was changed from disabled to auto start. Event[101]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:31.655 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Net.Msmq Listener Adapter service was changed from disabled to auto start. Event[102]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:12:48.655 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Net.Pipe Listener Adapter service was changed from disabled to auto start. Event[103]: Log Name: System Source: Microsoft-Windows-UserModePowerService Date: 2015-08-22T04:13:40.729 Event ID: 22 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Reapply power settings upon completion of the provisioning engine's turn 1 Event[104]: Log Name: System Source: Microsoft-Windows-Setup Date: 2015-08-22T04:13:40.951 Event ID: 2004 Task: OS information Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Successfully logged OS information Event[105]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:13:41.803 Event ID: 15 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Hive \??\C:\WINDOWS\System32\SMI\Store\Machine\SCHEMA.DAT was reorganized with a starting size of 8261632 bytes and an ending size of 7626752 bytes. Event[106]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:13:42.029 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\WINDOWS\system32\config\elam was cleared updating 0 keys and creating 0 modified pages. Event[107]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:13:57.648 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\Windows.old\Users\Default\NTUSER.DAT was cleared updating 0 keys and creating 0 modified pages. Event[108]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:13:57.737 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The server {4991D34B-80A1-4291-83B6-3328366B9097} did not register with DCOM within the required timeout. Event[109]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:14:00.018 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout. Event[110]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:14:00.018 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[111]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:15:10.193 Event ID: 7022 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Delivery Optimization service hung on starting. Event[112]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:16:00.023 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout. Event[113]: Log Name: System Source: Microsoft-Windows-Bits-Client Date: 2015-08-22T04:16:00.024 Event ID: 16392 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The BITS service failed to start. Error 0x80080005. Event[114]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:16:00.023 Event ID: 7024 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Background Intelligent Transfer Service service terminated with the following service-specific error: Server execution failed Event[115]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:16:00.023 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[116]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:18:00.029 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout. Event[117]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:18:00.075 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[118]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T04:20:00.081 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The server {A47979D2-C419-11D9-A5B4-001185AD2B89} did not register with DCOM within the required timeout. Event[119]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:00.081 Event ID: 7023 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Network List Service service terminated with the following error: The device is not ready. Event[120]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.722 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Canon Inkjet Printer/Scanner/Fax Extended Survey Program Service File Name: C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[121]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.738 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Adobe Acrobat Update Service Service File Name: "C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[122]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.754 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: SQL Server Browser Service File Name: "c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe" Service Type: user mode service Service Start Type: disabled Service Account: LocalSystem Event[123]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.754 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Intel(R) Rapid Storage Technology Service File Name: "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[124]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.769 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Apple Mobile Device Service File Name: "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[125]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.769 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: iPod Service Service File Name: "C:\Program Files\iPod\bin\iPodService.exe" Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[126]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.785 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Office Software Protection Platform Service File Name: "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[127]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.785 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: SQL Server Active Directory Helper Service File Name: "c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe" Service Type: user mode service Service Start Type: disabled Service Account: LocalSystem Event[128]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.800 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: SQL Server VSS Writer Service File Name: "c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[129]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.800 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: SQL Server (SQLEXPRESS) Service File Name: "c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[130]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.816 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: TomTomHOMEService Service File Name: "C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[131]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.816 Event ID: 7030 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The TomTomHOMEService service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. Event[132]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.816 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Bonjour Service Service File Name: "C:\Program Files\Bonjour\mDNSResponder.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[133]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.816 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Adobe Flash Player Update Service Service File Name: C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[134]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.832 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Office Source Engine Service File Name: "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[135]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.832 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Cisco AnyConnect Secure Mobility Agent Service File Name: "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe" Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem Event[136]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.847 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft SharePoint Workspace Audit Service Service File Name: "C:\Program Files\Microsoft Office\Office14\GROOVE.EXE" /auditservice Service Type: user mode service Service Start Type: demand start Service Account: LocalSystem Event[137]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.847 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: acsock Service File Name: system32\DRIVERS\acsock.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[138]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:20:20.847 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: GEAR ASPI Filter Driver Service File Name: system32\DRIVERS\GEARAspiWDM.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[139]: Log Name: System Source: User32 Date: 2015-08-22T04:20:49.301 Event ID: 1074 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The process C:\WINDOWS\system32\winlogon.exe (SURVEILLANCE1) has initiated the restart of computer SURVEILLANCE1 on behalf of user NT AUTHORITY\SYSTEM for the following reason: Operating System: Upgrade (Planned) Reason Code: 0x80020003 Shutdown Type: restart Comment: Event[140]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-22T04:20:49.878 Event ID: 51047 Task: Service State Event Level: Information Opcode: ServiceStop Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is stopped. ShutDown Flag value is 1 Event[141]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-22T04:20:49.910 Event ID: 50037 Task: Service State Event Level: Information Opcode: ServiceStop Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is stopped. ShutDown Flag value is 1 Event[142]: Log Name: System Source: EventLog Date: 2015-08-22T04:20:50.000 Event ID: 6006 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was stopped. Event[143]: Log Name: System Source: EventLog Date: 2015-08-22T04:22:21.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[144]: Log Name: System Source: EventLog Date: 2015-08-22T04:22:21.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[145]: Log Name: System Source: EventLog Date: 2015-08-22T04:22:22.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 70 seconds. Event[146]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-22T04:20:51.875 Event ID: 4001 Task: N/A Level: Information Opcode: Stop Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully stopped. Event[147]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-22T04:20:54.746 Event ID: 109 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The kernel power manager has initiated a shutdown transition. Shutdown Reason: Kernel API Event[148]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:20:57.212 Event ID: 13 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The operating system is shutting down at system time ?2015?-?08?-?22T08:20:57.212531400Z. Event[149]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:21:11.954 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?22T08:21:11.486597500Z. Event[150]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:21:11.954 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was true. The last boot's success status was true. Event[151]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:21:11.954 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[152]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:21:11.954 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[153]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:21:11.954 Event ID: 26 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A one-time boot sequence was used during this boot. Event[154]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T04:21:11.954 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[155]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:21:13.394 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[156]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:21:13.394 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[157]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-22T04:21:15.212 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[158]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:21:16.051 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[159]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:21:16.507 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[160]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-22T04:21:16.769 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[161]: Log Name: System Source: HECI Date: 2015-08-22T04:21:40.364 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[162]: Log Name: System Source: rt640x86 Date: 2015-08-22T04:21:40.922 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[163]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:21:41.028 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[164]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:21:41.029 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[165]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:21:41.068 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[166]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-22T04:21:41.193 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[167]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:22:21.323 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[168]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:22:21.356 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[169]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-22T04:22:22.813 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[170]: Log Name: System Source: Microsoft-Windows-Eventlog Date: 2015-08-22T04:22:22.962 Event ID: 22 Task: Service startup Level: Error Opcode: Info Keyword: Service availability User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The event logging service encountered an error while initializing publishing resources for channel DebugChannel. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well. Event[171]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-22T04:22:23.510 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[172]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-22T04:22:34.189 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[173]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:22:36.428 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[174]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:22:39.069 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Defender Network Inspection System Driver service depends on the Windows Defender Mini-Filter Driver service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[175]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-22T04:22:45.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[176]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:23:12.914 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[177]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T04:23:33.219 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The access history in hive \??\C:\Windows.old\Users\Default\NTUSER.DAT was cleared updating 0 keys and creating 0 modified pages. Event[178]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:23:47.450 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[179]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:24:15.093 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Distributed Transaction Coordinator service was changed from demand start to auto start. Event[180]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:24:20.234 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Distributed Transaction Coordinator service was changed from auto start to demand start. Event[181]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-22T04:25:38.702 Event ID: 4001 Task: N/A Level: Information Opcode: Stop Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully stopped. Event[182]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:25:54.084 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Distributed Transaction Coordinator service was changed from demand start to auto start. Event[183]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:25:58.293 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Distributed Transaction Coordinator service was changed from auto start to demand start. Event[184]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:03.951 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Task Scheduler service was changed from disabled to demand start. Event[185]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:04.404 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Task Scheduler service was changed from demand start to disabled. Event[186]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:04.869 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[187]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.000 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[188]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.383 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[189]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.407 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[190]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.438 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[191]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.458 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[192]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.533 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[193]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.569 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[194]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.586 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[195]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.594 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[196]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.608 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[197]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.635 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[198]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.662 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[199]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.715 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[200]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.800 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[201]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.806 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[202]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.837 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[203]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.854 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[204]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.873 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[205]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:05.987 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[206]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.313 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[207]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.350 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[208]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.424 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[209]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.436 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[210]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.464 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[211]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-22T04:26:06.493 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[212]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-22T04:26:12.521 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[213]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:14.656 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[214]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:14.923 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[215]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:14.923 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[216]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:15.157 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: Microsoft Tunnel Miniport Adapter Driver Service File Name: \SystemRoot\System32\drivers\tunnel.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[217]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[218]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[219]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[220]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[221]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[222]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:16.954 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[223]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:17.188 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[224]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:17.188 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[225]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:17.188 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[226]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:26:17.895 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver nettun.inf_x86_bf04828e355b121d\nettun.inf for Device Instance ID SWD\IP_TUNNEL_VBUS\ISATAP_0 with the following status: 0x0. Event[227]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:26:18.027 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver nettun.inf_x86_bf04828e355b121d\nettun.inf for Device Instance ID SWD\IP_TUNNEL_VBUS\TEREDO_TUNNEL_DEVICE with the following status: 0x0. Event[228]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:18.236 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[229]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:18.236 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[230]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:18.236 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[231]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.111 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[232]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.111 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[233]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.111 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[234]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.751 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[235]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.751 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[236]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:19.751 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[237]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:20.220 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[238]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:20.220 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[239]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:20.220 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[240]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T04:26:46.926 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[241]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:51.200 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Device Association Service service was changed from demand start to auto start. Event[242]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:52.434 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: WSD Print Support Service File Name: \SystemRoot\System32\drivers\WSDPrint.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[243]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:26:52.706 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver wsdprint.inf_x86_6d18a8078969e19d\wsdprint.inf for Device Instance ID SWD\DAFWSDPROVIDER\URN:UUID:00000000-0000-1000-8000-60128B4068B3/HTTP://SCHEMAS.CANON.COM/PRINTER with the following status: 0x0. Event[244]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:55.654 Event ID: 7045 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: A service was installed in the system. Service Name: WSD Scan Support Service File Name: \SystemRoot\system32\DRIVERS\WSDScan.sys Service Type: kernel mode driver Service Start Type: demand start Service Account: Event[245]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:26:55.658 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service WSDScan for Device Instance ID SWD\DAFWSDPROVIDER\URN:UUID:00000000-0000-1000-8000-60128B4068B3/HTTP://SCHEMAS.CANON.COM/SCANNER with the following status: 0. Event[246]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:26:55.815 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver wsdscdrv.inf_x86_5fed09537d0fefdc\wsdscdrv.inf for Device Instance ID SWD\DAFWSDPROVIDER\URN:UUID:00000000-0000-1000-8000-60128B4068B3/HTTP://SCHEMAS.CANON.COM/SCANNER with the following status: 0x0. Event[247]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:26:55.872 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Image Acquisition (WIA) service was changed from demand start to auto start. Event[248]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-22T04:27:01.987 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver mg2900p3.inf_x86_01a75290d1f29f5b\mg2900p3.inf for Device Instance ID SWD\PRINTENUM\WSD-46B5DC6C-6C50-47B7-8293-6822B5521B59.006D with the following status: 0x0. Event[249]: Log Name: System Source: NETLOGON Date: 2015-08-22T04:27:06.000 Event ID: 3095 Task: N/A Level: Error Opcode: Info Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: This computer is configured as a member of a workgroup, not as a member of a domain. The Netlogon service does not need to run in this configuration. Event[250]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:27:09.918 Event ID: 7024 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The BranchCache service terminated with the following service-specific error: This program is blocked by group policy. For more information, contact your system administrator. Event[251]: Log Name: System Source: Service Control Manager Date: 2015-08-22T04:28:15.513 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Defender Network Inspection System Driver service was changed from auto start to demand start. Event[252]: Log Name: System Source: Microsoft-Windows-TPM-WMI Date: 2015-08-22T04:28:16.212 Event ID: 1281 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: This event triggers the TBS device identifier generation. Event[253]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:26:49.255 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?22T11:26:49.240004100Z from ?2015?-?08?-?22T11:26:49.240004100Z. Change Reason: System time adjusted to the new time zone. Event[254]: Log Name: System Source: Microsoft-Windows-TPM-WMI Date: 2015-08-22T07:26:55.519 Event ID: 1282 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The TBS device identifier has been generated. Event[255]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-22T07:26:59.658 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[256]: Log Name: System Source: Microsoft-Windows-GroupPolicy Date: 2015-08-22T07:27:00.573 Event ID: 1501 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The Group Policy settings for the user were processed successfully. There were no changes detected since the last successful processing of Group Policy. Event[257]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:13.059 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Microsoft.AAD.BrokerPlugin_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[258]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:17.385 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Microsoft.Windows.CloudExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[259]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:19.283 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[260]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:20.703 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[261]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:21.276 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Microsoft.AccountsControl_10.0.10240.16384_neutral__cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[262]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:21.725 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Microsoft.BioEnrollment_10.0.10240.16384_neutral__cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[263]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:22.110 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Microsoft.LockApp_10.0.10240.16384_neutral__cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[264]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:22.615 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Microsoft.MicrosoftEdge_20.10240.16384.0_neutral__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[265]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:23.111 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Microsoft.Windows.AssignedAccessLockApp_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[266]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:23.501 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Microsoft.Windows.ContentDeliveryManager_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[267]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:23.834 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Microsoft.Windows.ParentalControls_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[268]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:24.233 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsFeedback_cw5n1h2txyewy\Microsoft.WindowsFeedback_10.0.10240.16393_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[269]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:24.562 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Microsoft.XboxGameCallableUI_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[270]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:24.929 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxIdentityProvider_cw5n1h2txyewy\Microsoft.XboxIdentityProvider_1000.10240.16384.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[271]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:25.290 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.ContactSupport_cw5n1h2txyewy\Windows.ContactSupport_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[272]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:26.038 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.PurchaseDialog_cw5n1h2txyewy\Windows.PurchaseDialog_6.2.0.0_neutral_neutral_cw5n1h2txyewy\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[273]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:27.976 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\microsoft.windowscommunicationsapps_17.6002.42251.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[274]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:32.889 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[275]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:34.129 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Microsoft.BingNews_4.3.193.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[276]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:38.475 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Microsoft.BingWeather_4.3.193.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[277]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:40.968 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[278]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:43.140 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[279]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:43.206 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Microsoft.Getstarted_2.1.9.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[280]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:47.760 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Microsoft.Windows.Photos_15.618.18170.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[281]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:50.390 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Microsoft.WindowsCamera_5.38.3003.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[282]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:51.712 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Microsoft.WindowsStore_2015.7.1.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[283]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:53.824 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Microsoft.XboxApp_5.6.17000.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[284]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:27:57.181 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Microsoft.ZuneMusic_3.6.10841.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[285]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:28:05.916 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\Microsoft.BingFinance_4.3.193.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[286]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:28:15.531 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[287]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:28:32.611 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[288]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:13.129 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[289]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:13.487 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.AccountsControl_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[290]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:14.629 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[291]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:14.718 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[292]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:14.817 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[293]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:14.879 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BioEnrollment_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[294]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.065 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[295]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.300 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.LockApp_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[296]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.414 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[297]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.473 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.NET.Native.Framework.1.0_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[298]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.613 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.NET.Native.Runtime.1.0_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[299]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.675 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.VCLibs.140.00_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[300]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.743 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.AssignedAccessLockApp_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[301]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.800 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[302]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:15.941 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.ParentalControls_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[303]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.097 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[304]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.222 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[305]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.409 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsFeedback_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[306]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.473 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[307]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.535 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxGameCallableUI_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[308]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:16.691 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxIdentityProvider_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[309]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:17.071 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[310]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:17.228 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.ContactSupport_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[311]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:17.363 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\windows.immersivecontrolpanel_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[312]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:17.581 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.MiracastView_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[313]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:18.316 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.PrintDialog_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[314]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:29:18.418 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Windows.PurchaseDialog_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[315]: Log Name: System Source: Microsoft-Windows-Time-Service Date: 2015-08-22T07:43:21.854 Event ID: 37 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The time provider NtpClient is currently receiving valid time data from time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->104.41.150.68:123). Event[316]: Log Name: System Source: Microsoft-Windows-Time-Service Date: 2015-08-22T07:43:21.967 Event ID: 158 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well. Event[317]: Log Name: System Source: Service Control Manager Date: 2015-08-22T07:43:24.279 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[318]: Log Name: System Source: Service Control Manager Date: 2015-08-22T07:46:58.561 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[319]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:48:26.884 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Microsoft.WindowsAlarms_10.1506.19010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[320]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:48:52.476 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Microsoft.SkypeApp_3.2.1.0_x86__kzf8qxf38zg5c\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[321]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:49:01.042 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Microsoft.ZuneVideo_3.6.10811.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[322]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:49:09.121 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Microsoft.WindowsSoundRecorder_10.1506.15100.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[323]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:49:22.392 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsPhone_8wekyb3d8bbwe\Microsoft.WindowsPhone_10.1506.20010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[324]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:49:34.889 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Microsoft.WindowsMaps_4.1505.50619.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[325]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:50:45.789 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Microsoft.WindowsCalculator_10.1506.19010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[326]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:51:48.703 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Microsoft.People_1.10159.0.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[327]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:51:56.636 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Microsoft.Office.OneNote_17.4201.10091.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[328]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:52:30.247 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Microsoft.MicrosoftSolitaireCollection_3.1.6103.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[329]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:52:34.684 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Microsoft.MicrosoftOfficeHub_17.4218.23751.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[330]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:52:37.800 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\Microsoft.BingSports_4.3.193.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[331]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:52:40.953 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Appconnector_8wekyb3d8bbwe\Microsoft.Appconnector_1.3.3.0_neutral__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[332]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T07:52:45.655 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.3DBuilder_8wekyb3d8bbwe\Microsoft.3DBuilder_10.0.0.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[333]: Log Name: System Source: Service Control Manager Date: 2015-08-22T07:59:18.960 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[334]: Log Name: System Source: Service Control Manager Date: 2015-08-22T08:01:38.452 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[335]: Log Name: System Source: Service Control Manager Date: 2015-08-22T08:06:24.823 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[336]: Log Name: System Source: User32 Date: 2015-08-22T08:11:51.602 Event ID: 1074 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The process C:\Windows\System32\RuntimeBroker.exe (SURVEILLANCE1) has initiated the power off of computer SURVEILLANCE1 on behalf of user Surveillance1\Surveillance for the following reason: Other (Unplanned) Reason Code: 0x0 Shutdown Type: power off Comment: Event[337]: Log Name: System Source: Service Control Manager Date: 2015-08-22T08:11:59.329 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[338]: Log Name: System Source: Service Control Manager Date: 2015-08-22T08:12:02.625 Event ID: 7031 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Sync Host_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Event[339]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-22T08:12:04.818 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The server CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca did not register with DCOM within the required timeout. Event[340]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-22T08:12:12.030 Event ID: 7002 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logoff Notification for Customer Experience Improvement Program Event[341]: Log Name: System Source: EventLog Date: 2015-08-22T18:57:59.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 52608 seconds. Event[342]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-22T08:12:13.461 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Application API Event[343]: Log Name: System Source: BROWSER Date: 2015-08-22T18:58:04.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[344]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T18:57:59.499 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?22T22:57:59.500000000Z from ?2015?-?08?-?22T12:12:15.974842900Z. Change Reason: System time synchronized with the hardware clock. Event[345]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T18:58:01.593 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[346]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T18:58:01.593 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot type was 0x1. Event[347]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T18:58:01.593 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[348]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T18:58:01.596 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[349]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-22T18:58:05.618 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?22T12:12:12.961001500Z Wake Time: ?2015?-?08?-?22T22:58:01.603425800Z Wake Source: Unknown Event[350]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-22T18:58:10.609 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[351]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[352]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[353]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[354]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[355]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[356]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:03:22.013 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[357]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:03:42.555 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[358]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:03:43.350 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[359]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:05.100 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[360]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:09.230 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[361]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:11.178 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[362]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:11.509 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[363]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:16.690 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[364]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:16.937 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[365]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:53.479 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[366]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:07:55.739 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[367]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-22T19:07:55.960 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume ?? (\Device\HarddiskVolumeShadowCopy2) is healthy. No action is needed. Event[368]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:07:56.947 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Update for Windows 10 (KB3074678) Event[369]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:01.947 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Update for Windows 10 (KB3074678) Event[370]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:09.032 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[371]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-22T19:08:11.095 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume ?? (\Device\HarddiskVolumeShadowCopy3) is healthy. No action is needed. Event[372]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:11.169 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[373]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:13.623 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Update for Windows 10 (KB3074686) Event[374]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:13.623 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Update for Windows 10 (KB3074686) Event[375]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:13.623 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Update for Windows 10 (KB3081704) Event[376]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:43.355 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[377]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:44.833 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[378]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:45.188 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from demand start to auto start. Event[379]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:08:47.996 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Modules Installer service was changed from auto start to demand start. Event[380]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:48.104 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Update for Windows 10 (KB3081704) Event[381]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:48.104 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Security Update for Internet Explorer Flash Player for Windows 10 (KB3087916) Event[382]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:48.104 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Security Update for Internet Explorer Flash Player for Windows 10 (KB3087916) Event[383]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:48.104 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Update for Windows 10 (KB3081441) Event[384]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:08:49.288 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsDVDPlayer_8wekyb3d8bbwe\Microsoft.WindowsDVDPlayer_3.6.11761.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[385]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:53.105 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Update for Windows 10 (KB3081441) Event[386]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:08:53.105 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.263.0) Event[387]: Log Name: System Source: Service Control Manager Date: 2015-08-22T19:09:33.159 Event ID: 7040 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The start type of the Windows Defender Network Inspection System Driver service was changed from demand start to auto start. Event[388]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:09:39.555 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.263.0) Event[389]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:24.418 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[390]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:24.419 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[391]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:28.386 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[392]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:47.071 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[393]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:52.067 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Visual C++ 2015 Runtime Package Event[394]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:16:56.105 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingNews_8wekyb3d8bbwe\Microsoft.BingNews_4.4.200.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[395]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:57.896 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Visual C++ 2015 Runtime Package Event[396]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:16:57.896 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: MSN News Event[397]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:17:01.252 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Microsoft.WindowsCalculator_10.1507.15010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[398]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:03.431 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: MSN News Event[399]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:03.431 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Visual C++ 2015 Runtime Package Event[400]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:03.431 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Calculator Event[401]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:17:05.436 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingFinance_8wekyb3d8bbwe\Microsoft.BingFinance_4.4.200.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[402]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Calculator Event[403]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[404]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Visual C++ 2015 Runtime Package Event[405]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: MSN Money Event[406]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: MSN Money Event[407]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:14.389 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[408]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:18.561 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[409]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:17:30.401 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Getstarted_8wekyb3d8bbwe\Microsoft.Getstarted_2.2.7.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[410]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:32.072 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Get Started Event[411]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:17:36.520 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.People_8wekyb3d8bbwe\Microsoft.People_1.10241.0.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[412]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:38.333 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Get Started Event[413]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:38.333 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft People Event[414]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:17:43.501 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingWeather_8wekyb3d8bbwe\Microsoft.BingWeather_4.4.200.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[415]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:51.987 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[416]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:51.987 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft People Event[417]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:51.987 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: MSN Weather Event[418]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:51.987 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: MSN Weather Event[419]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:51.987 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[420]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:17:56.070 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[421]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:18:09.119 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.3DBuilder_8wekyb3d8bbwe\Microsoft.3DBuilder_10.1.9.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[422]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:11.038 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: 3D Builder Event[423]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:11.038 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: 3D Builder Event[424]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:18:13.963 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.BingSports_8wekyb3d8bbwe\Microsoft.BingSports_4.4.200.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[425]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:16.932 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: MSN Sports Event[426]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:16.932 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: MSN Sports Event[427]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:16.932 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Voice Recorder Event[428]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:18:18.102 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Microsoft.WindowsSoundRecorder_10.1507.7010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[429]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:18.407 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[430]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:41.974 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Voice Recorder Event[431]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:41.992 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[432]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:41.992 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[433]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:18:44.682 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[434]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:08.406 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Phone Companion Event[435]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:08.406 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Phone Companion Event[436]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.573 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Alarms & Clock Event[437]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.573 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Alarms & Clock Event[438]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.573 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Maps Event[439]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.573 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Maps Event[440]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.574 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[441]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:24.574 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[442]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:28.412 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[443]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:57.726 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Pel·lícules i programes Event[444]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:57.726 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Pel·lícules i programes Event[445]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:19:57.726 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Xbox Event[446]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:08.896 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Xbox Event[447]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:08.896 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[448]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:16.855 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[449]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:16.855 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Groove Music Event[450]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:16.855 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Groove Music Event[451]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:20.555 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[452]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:39.832 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Camera Event[453]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:39.832 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Camera Event[454]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:39.832 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Store Event[455]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:39.833 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Store Event[456]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:39.833 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[457]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:20:43.810 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[458]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:15.418 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Get Office Event[459]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:15.418 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Get Office Event[460]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:15.418 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[461]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:21.583 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Voice Recorder Event[462]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:21.583 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Voice Recorder Event[463]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:32.260 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: OneNote Event[464]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:32.260 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: OneNote Event[465]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:32.260 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Photos Event[466]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:37.392 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[467]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:21:37.392 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Photos Event[468]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:22:15.563 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Mail and Calendar Event[469]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:22:15.563 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Mail and Calendar Event[470]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:22:20.566 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Solitaire Collection Event[471]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-22T19:22:20.566 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Solitaire Collection Event[472]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-22T19:33:01.744 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?22T23:33:01.486559000Z. Event[473]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T19:33:01.744 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[474]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T19:33:01.744 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[475]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T19:33:01.744 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[476]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T19:33:01.744 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[477]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-22T19:33:01.744 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[478]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T19:33:03.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[479]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T19:33:03.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[480]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T19:33:03.206 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[481]: Log Name: System Source: EventLog Date: 2015-08-22T19:33:43.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 7:10:22 PM on ?8/?22/?2015 was unexpected. Event[482]: Log Name: System Source: EventLog Date: 2015-08-22T19:33:43.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[483]: Log Name: System Source: EventLog Date: 2015-08-22T19:33:43.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[484]: Log Name: System Source: EventLog Date: 2015-08-22T19:33:44.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 42 seconds. Event[485]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-22T19:33:07.608 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[486]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-22T19:33:08.676 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[487]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T12:36:16.743 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?23T16:36:16.486537300Z. Event[488]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T12:36:16.743 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[489]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T12:36:16.743 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[490]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T12:36:16.743 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[491]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T12:36:16.743 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[492]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T12:36:16.743 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[493]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:18.735 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[494]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:18.736 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[495]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:18.736 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[496]: Log Name: System Source: EventLog Date: 2015-08-23T12:36:57.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 7:33:44 PM on ?8/?22/?2015 was unexpected. Event[497]: Log Name: System Source: EventLog Date: 2015-08-23T12:36:57.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[498]: Log Name: System Source: EventLog Date: 2015-08-23T12:36:57.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[499]: Log Name: System Source: EventLog Date: 2015-08-23T12:36:57.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 40 seconds. Event[500]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-23T12:36:25.204 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[501]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:25.458 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[502]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:25.552 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[503]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T12:36:25.565 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[504]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T12:36:25.565 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[505]: Log Name: System Source: HECI Date: 2015-08-23T12:36:28.832 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[506]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T12:36:29.586 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[507]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T12:36:29.602 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[508]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T12:36:29.603 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[509]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T12:36:29.604 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[510]: Log Name: System Source: rt640x86 Date: 2015-08-23T12:36:31.870 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[511]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:56.120 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[512]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T12:36:56.159 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[513]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-23T12:36:58.404 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[514]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-23T12:36:58.828 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[515]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.154 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[516]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.158 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[517]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.893 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[518]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.903 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[519]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.907 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[520]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.909 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[521]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.979 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[522]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.981 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[523]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.990 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[524]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:03.993 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[525]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.001 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[526]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.007 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[527]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.348 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[528]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.472 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[529]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.595 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[530]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.598 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[531]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.613 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[532]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.623 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[533]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.667 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[534]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:04.675 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[535]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-23T12:37:04.905 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[536]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:07.137 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[537]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-23T12:37:14.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[538]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:13.977 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[539]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:13.981 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[540]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:14.187 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[541]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:14.189 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[542]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:14.816 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[543]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T12:37:14.832 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[544]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:45.239 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[545]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:45.239 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[546]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:45.411 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[547]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:45.411 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[548]: Log Name: System Source: Service Control Manager Date: 2015-08-23T12:37:45.411 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[549]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T12:37:56.045 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[550]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T12:37:58.680 Event ID: 5 Task: N/A Level: Error Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: {Registry Hive Recovered} Registry hive (file): '\??\C:\WINDOWS\AppCompat\Programs\Amcache.hve' was corrupted and it has been recovered. Some data might have been lost. Event[551]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T12:43:40.946 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[552]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T12:44:36.213 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.303.0) Event[553]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T12:44:50.346 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.303.0) Event[554]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T13:54:26.744 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?23T17:54:26.486515100Z. Event[555]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T13:54:26.745 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[556]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T13:54:26.745 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[557]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T13:54:26.745 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[558]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T13:54:26.745 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[559]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T13:54:26.745 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[560]: Log Name: System Source: EventLog Date: 2015-08-23T13:54:54.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 1:51:35 PM on ?8/?23/?2015 was unexpected. Event[561]: Log Name: System Source: EventLog Date: 2015-08-23T13:54:54.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[562]: Log Name: System Source: EventLog Date: 2015-08-23T13:54:54.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[563]: Log Name: System Source: EventLog Date: 2015-08-23T13:54:54.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 27 seconds. Event[564]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:28.204 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[565]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:28.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[566]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:28.206 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[567]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-23T13:54:34.963 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[568]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:35.137 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[569]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:35.234 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[570]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T13:54:35.246 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[571]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T13:54:35.247 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[572]: Log Name: System Source: HECI Date: 2015-08-23T13:54:37.973 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[573]: Log Name: System Source: rt640x86 Date: 2015-08-23T13:54:38.686 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[574]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T13:54:38.818 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[575]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T13:54:38.820 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[576]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T13:54:38.821 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[577]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T13:54:38.822 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[578]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:53.660 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[579]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T13:54:53.670 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[580]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-23T13:54:55.243 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[581]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-23T13:54:55.269 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[582]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:56.328 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[583]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:56.330 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[584]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.079 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[585]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.101 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[586]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.105 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[587]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.107 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[588]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.127 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[589]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.128 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[590]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.134 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[591]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.136 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[592]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.145 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[593]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.149 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[594]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.158 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[595]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-23T13:54:57.182 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[596]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.187 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[597]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.214 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[598]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.217 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[599]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.230 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[600]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.241 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[601]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.253 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[602]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:54:57.493 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[603]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:54:57.519 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[604]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-23T13:55:01.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[605]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.527 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[606]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.529 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[607]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.545 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[608]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.547 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[609]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.681 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[610]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T13:55:01.719 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[611]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:55:16.199 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[612]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T13:55:23.763 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[613]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:55:52.178 Event ID: 7024 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Search service terminated with the following service-specific error: %%2147749126 Event[614]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:55:52.178 Event ID: 7031 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Event[615]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:56:03.594 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. Event[616]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:56:03.594 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[617]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T13:56:03.610 Event ID: 10005 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: DCOM got error "1053" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {B52D54BB-4818-4EB9-AA80-F9EACD371DF8} Event[618]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:56:07.454 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect. Event[619]: Log Name: System Source: Service Control Manager Date: 2015-08-23T13:56:07.454 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[620]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T13:56:07.454 Event ID: 10005 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: DCOM got error "1053" attempting to start the service WSearch with arguments "Unavailable" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Event[621]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T13:58:35.850 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[622]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T13:59:07.981 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.308.0) Event[623]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T13:59:24.837 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.308.0) Event[624]: Log Name: System Source: BROWSER Date: 2015-08-23T15:41:53.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[625]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T14:27:37.910 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[626]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T14:27:37.927 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[627]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T15:41:52.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?23T19:41:52.500000000Z from ?2015?-?08?-?23T18:27:39.810010500Z. Change Reason: System time synchronized with the hardware clock. Event[628]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-23T15:42:05.616 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?23T18:27:33.875589900Z Wake Time: ?2015?-?08?-?23T19:41:53.732630500Z Wake Source: Power Button Event[629]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T15:42:06.828 Event ID: 10001 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: Unable to start a DCOM Server: App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca as Unavailable/Unavailable. The error: "31" Happened while starting this command: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXwmnqm0nvq2b90pwvr42qmtdjp7cj3w82.mca Event[630]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T15:42:49.131 Event ID: 10016 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Event[631]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T16:01:17.246 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[632]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T16:01:17.274 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[633]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T16:18:08.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?23T20:18:08.500000000Z from ?2015?-?08?-?23T20:01:18.782325800Z. Change Reason: System time synchronized with the hardware clock. Event[634]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-23T16:18:14.685 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?23T20:01:15.550329400Z Wake Time: ?2015?-?08?-?23T20:18:09.696074100Z Wake Source: Power Button Event[635]: Log Name: System Source: Microsoft-Windows-DNS-Client Date: 2015-08-23T16:18:16.291 Event ID: 1014 Task: N/A Level: Warning Opcode: Info Keyword: N/A User: S-1-5-20 User Name: NT AUTHORITY\NETWORK SERVICE Computer: Surveillance1 Description: Name resolution for the name wpad timed out after none of the configured DNS servers responded. Event[636]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-23T16:18:16.587 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service usbser for Device Instance ID USB\VID_1004&PID_61FA&MI_00\7&64BD54F&0&0000 with the following status: 0. Event[637]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-23T16:18:19.515 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver usbser.inf_x86_a8077066161f8bba\usbser.inf for Device Instance ID USB\VID_1004&PID_61FA&MI_00\7&64BD54F&0&0000 with the following status: 0x0. Event[638]: Log Name: System Source: User32 Date: 2015-08-23T16:34:16.975 Event ID: 1074 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The process C:\Windows\System32\RuntimeBroker.exe (SURVEILLANCE1) has initiated the power off of computer SURVEILLANCE1 on behalf of user Surveillance1\Surveillance for the following reason: Other (Unplanned) Reason Code: 0x0 Shutdown Type: power off Comment: Event[639]: Log Name: System Source: Service Control Manager Date: 2015-08-23T16:34:17.480 Event ID: 7031 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Sync Host_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Event[640]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T16:34:19.654 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The server CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca did not register with DCOM within the required timeout. Event[641]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-23T16:34:19.670 Event ID: 10001 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: Unable to start a DCOM Server: CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mca as Unavailable/Unavailable. The error: "31" Happened while starting this command: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca Event[642]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T16:34:23.265 Event ID: 7002 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logoff Notification for Customer Experience Improvement Program Event[643]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T16:34:27.783 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Application API Event[644]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:26:47.498 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?23T22:26:47.500000000Z from ?2015?-?08?-?23T20:34:29.489358700Z. Change Reason: System time synchronized with the hardware clock. Event[645]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:26:48.185 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[646]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:26:48.185 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot type was 0x1. Event[647]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:26:48.185 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[648]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:26:48.185 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[649]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-23T18:26:53.274 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?23T20:34:24.038110800Z Wake Time: ?2015?-?08?-?23T22:26:51.362308300Z Wake Source: Unknown Event[650]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T18:26:54.829 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[651]: Log Name: System Source: Microsoft-Windows-DNS-Client Date: 2015-08-23T18:26:55.654 Event ID: 1014 Task: N/A Level: Warning Opcode: Info Keyword: N/A User: S-1-5-20 User Name: NT AUTHORITY\NETWORK SERVICE Computer: Surveillance1 Description: Name resolution for the name wpad timed out after none of the configured DNS servers responded. Event[652]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:21.221 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[653]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:21.221 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[654]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:24.315 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[655]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:30:32.726 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsSoundRecorder_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[656]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:35.054 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Voice Recorder Event[657]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:30:37.700 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftSolitaireCollection_8wekyb3d8bbwe\Microsoft.MicrosoftSolitaireCollection_3.3.8040.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[658]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:30:44.204 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Microsoft.Windows.Photos_15.803.16240.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[659]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:45.345 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Voice Recorder Event[660]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:45.345 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Solitaire Collection Event[661]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:45.345 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Solitaire Collection Event[662]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:45.345 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Photos Event[663]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:45.345 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[664]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:54.517 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[665]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:54.517 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Photos Event[666]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:58.109 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[667]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:30:58.110 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Maps Event[668]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:30:58.151 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Microsoft.WindowsMaps_4.1507.50813.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[669]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:02.815 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Microsoft.WindowsAlarms_10.1508.17010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[670]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:05.125 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsAlarms_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[671]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:05.646 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Maps Event[672]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:05.646 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Alarms & Clock Event[673]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:09.731 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.ZuneVideo_8wekyb3d8bbwe\Microsoft.ZuneVideo_3.6.12391.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[674]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:11.640 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Alarms & Clock Event[675]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:11.640 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[676]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:11.640 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Pel·lícules i programes Event[677]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:19.491 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[678]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:19.491 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Pel·lícules i programes Event[679]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:24.372 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[680]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:24.372 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Xbox Event[681]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:26.408 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.XboxApp_8wekyb3d8bbwe\Microsoft.XboxApp_8.8.15003.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[682]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:30.372 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Xbox Event[683]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:35.836 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.ZuneMusic_8wekyb3d8bbwe\Microsoft.ZuneMusic_3.6.12391.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[684]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:36.121 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Groove Music Event[685]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:40.475 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[686]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:47.065 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Microsoft.WindowsStore_2015.8.12.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[687]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:50.095 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Groove Music Event[688]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:31:50.095 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Store Event[689]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:31:52.215 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Microsoft.WindowsCamera_5.49.3001.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[690]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:04.350 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Store Event[691]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:04.350 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[692]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:04.350 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Camera Event[693]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:04.350 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Camera Event[694]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:04.350 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[695]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:09.058 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[696]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:23.331 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: OneNote Event[697]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:24.778 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Microsoft.Office.OneNote_17.6027.10061.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[698]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:37.185 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: OneNote Event[699]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:37.185 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Get Office Event[700]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:37.840 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Microsoft.MicrosoftOfficeHub_17.6106.23501.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[701]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:42.127 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[702]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:42.127 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Get Office Event[703]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:42.127 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Mail and Calendar Event[704]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:44.610 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\microsoft.windowscommunicationsapps_17.6120.42011.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[705]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:47.420 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[706]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:55.979 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Mail and Calendar Event[707]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:32:55.979 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Phone Companion Event[708]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:56.187 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsPhone_8wekyb3d8bbwe\Microsoft.WindowsPhone_10.1508.17010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[709]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:58.649 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsPhone_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[710]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:32:59.245 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsPhone_8wekyb3d8bbwe\Microsoft.WindowsPhone_10.1508.17010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[711]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:33:02.568 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Phone Companion Event[712]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:33:02.568 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Phone Companion Event[713]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-23T18:33:02.568 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Phone Companion Event[714]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:40:02.744 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?23T22:40:02.486550900Z. Event[715]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:40:02.744 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[716]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:40:02.744 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[717]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:40:02.744 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[718]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:40:02.745 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[719]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:40:02.745 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[720]: Log Name: System Source: EventLog Date: 2015-08-23T18:40:23.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 6:26:50 PM on ?8/?23/?2015 was unexpected. Event[721]: Log Name: System Source: EventLog Date: 2015-08-23T18:40:23.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[722]: Log Name: System Source: EventLog Date: 2015-08-23T18:40:23.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[723]: Log Name: System Source: EventLog Date: 2015-08-23T18:40:23.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 20 seconds. Event[724]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:04.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[725]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:04.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[726]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:04.222 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[727]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-23T18:40:09.202 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[728]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:09.581 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[729]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:09.696 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[730]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:40:09.709 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[731]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:40:09.709 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[732]: Log Name: System Source: HECI Date: 2015-08-23T18:40:12.410 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[733]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:40:13.107 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[734]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:40:13.107 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[735]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:40:13.145 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[736]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:40:13.286 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[737]: Log Name: System Source: rt640x86 Date: 2015-08-23T18:40:15.284 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[738]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:22.348 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[739]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:40:22.351 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[740]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-23T18:40:24.762 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[741]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-23T18:40:24.800 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[742]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:25.932 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[743]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:25.935 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[744]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-23T18:40:27.515 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[745]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.363 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[746]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.390 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[747]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.396 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[748]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.399 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[749]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.432 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[750]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.435 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[751]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.444 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[752]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.448 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[753]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.462 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[754]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.470 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[755]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:28.495 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[756]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:40:29.330 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[757]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.478 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[758]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.511 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[759]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.514 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[760]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.527 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[761]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.538 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[762]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.552 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[763]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:29.561 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[764]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-23T18:40:34.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[765]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.195 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[766]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.197 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[767]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.215 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[768]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.217 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[769]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.381 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[770]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:40:34.397 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[771]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T18:40:47.645 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[772]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T18:44:11.745 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?23T22:44:11.486566300Z. Event[773]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:44:11.745 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[774]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:44:11.745 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[775]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:44:11.745 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[776]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:44:11.745 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[777]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T18:44:11.745 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[778]: Log Name: System Source: EventLog Date: 2015-08-23T18:44:32.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 6:40:23 PM on ?8/?23/?2015 was unexpected. Event[779]: Log Name: System Source: EventLog Date: 2015-08-23T18:44:32.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[780]: Log Name: System Source: EventLog Date: 2015-08-23T18:44:32.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[781]: Log Name: System Source: EventLog Date: 2015-08-23T18:44:32.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 21 seconds. Event[782]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:13.204 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[783]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:13.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[784]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:13.206 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[785]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-23T18:44:21.160 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[786]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:21.306 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[787]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:21.421 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[788]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:44:21.433 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[789]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:44:21.434 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[790]: Log Name: System Source: HECI Date: 2015-08-23T18:44:23.098 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[791]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:44:23.695 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[792]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:44:23.698 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[793]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:44:23.698 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[794]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T18:44:23.700 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[795]: Log Name: System Source: rt640x86 Date: 2015-08-23T18:44:25.596 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[796]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:32.065 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[797]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T18:44:32.068 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[798]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-23T18:44:34.032 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[799]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-23T18:44:34.070 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[800]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:35.219 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[801]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:35.222 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[802]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.695 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[803]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-23T18:44:36.703 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[804]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.714 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[805]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.721 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[806]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.723 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[807]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.871 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[808]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.888 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[809]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.894 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[810]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.895 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[811]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.902 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[812]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.906 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[813]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.912 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[814]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.929 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[815]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.950 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[816]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.951 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[817]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.959 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[818]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.966 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[819]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.977 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[820]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:36.983 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[821]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:44:39.991 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[822]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-23T18:44:42.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[823]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.418 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[824]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.424 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[825]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.446 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[826]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.448 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[827]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.826 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[828]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T18:44:42.867 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[829]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T18:45:04.734 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[830]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:45:12.480 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[831]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:45:12.480 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[832]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:45:13.043 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[833]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:45:13.043 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[834]: Log Name: System Source: Service Control Manager Date: 2015-08-23T18:45:13.058 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[835]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:53:37.181 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[836]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T18:53:37.184 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[837]: Log Name: System Source: BROWSER Date: 2015-08-23T19:19:24.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[838]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T19:19:23.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?23T23:19:23.500000000Z from ?2015?-?08?-?23T22:53:41.146991500Z. Change Reason: System time synchronized with the hardware clock. Event[839]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-23T19:19:28.544 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?23T22:53:32.200391000Z Wake Time: ?2015?-?08?-?23T23:19:24.725754500Z Wake Source: Power Button Event[840]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T19:19:38.247 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.MicrosoftOfficeHub_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages. Event[841]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-23T19:40:42.748 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?23T23:40:42.486540400Z. Event[842]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T19:40:42.748 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[843]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T19:40:42.748 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[844]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T19:40:42.748 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[845]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T19:40:42.748 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[846]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-23T19:40:42.749 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[847]: Log Name: System Source: EventLog Date: 2015-08-23T19:41:04.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 7:19:28 PM on ?8/?23/?2015 was unexpected. Event[848]: Log Name: System Source: EventLog Date: 2015-08-23T19:41:04.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[849]: Log Name: System Source: EventLog Date: 2015-08-23T19:41:04.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[850]: Log Name: System Source: EventLog Date: 2015-08-23T19:41:04.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 22 seconds. Event[851]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:40:44.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[852]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:40:44.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[853]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:40:44.222 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[854]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-23T19:41:13.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[855]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-23T19:40:48.997 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[856]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:40:49.565 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[857]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:40:49.663 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[858]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T19:40:49.676 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[859]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T19:40:49.677 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[860]: Log Name: System Source: HECI Date: 2015-08-23T19:40:52.692 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[861]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T19:40:53.526 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[862]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T19:40:53.528 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[863]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T19:40:53.529 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[864]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-23T19:40:53.645 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[865]: Log Name: System Source: rt640x86 Date: 2015-08-23T19:40:55.773 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[866]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:41:03.453 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[867]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-23T19:41:03.455 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[868]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-23T19:41:06.107 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[869]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-23T19:41:06.123 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[870]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:07.176 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[871]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:07.177 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[872]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.600 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[873]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.633 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[874]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.651 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[875]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.653 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[876]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.670 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[877]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.671 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[878]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.676 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[879]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.677 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[880]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.684 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[881]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.688 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[882]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.709 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[883]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.726 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[884]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.747 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[885]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.748 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[886]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.756 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[887]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.762 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[888]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.771 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[889]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:09.778 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[890]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-23T19:41:11.023 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[891]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:11.292 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[892]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:20.154 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[893]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:20.157 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[894]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:20.183 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[895]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:20.185 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[896]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:21.130 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[897]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-23T19:41:21.148 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[898]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:45.128 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[899]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:45.128 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[900]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:45.347 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[901]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:45.347 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[902]: Log Name: System Source: Service Control Manager Date: 2015-08-23T19:41:45.347 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[903]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-23T19:41:57.340 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[904]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T19:48:37.458 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[905]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-23T19:48:37.460 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[906]: Log Name: System Source: BROWSER Date: 2015-08-24T07:14:36.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[907]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T07:14:35.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?24T11:14:35.500000000Z from ?2015?-?08?-?23T23:48:43.352182300Z. Change Reason: System time synchronized with the hardware clock. Event[908]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-24T07:14:41.991 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?23T23:48:33.133855400Z Wake Time: ?2015?-?08?-?24T11:14:36.730611500Z Wake Source: Power Button Event[909]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T07:15:27.892 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[910]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T07:16:16.104 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.364.0) Event[911]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T07:16:34.195 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.364.0) Event[912]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T07:45:17.380 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[913]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T07:45:17.382 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[914]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T09:39:02.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?24T13:39:02.500000000Z from ?2015?-?08?-?24T11:45:21.514877100Z. Change Reason: System time synchronized with the hardware clock. Event[915]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-24T09:39:09.108 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?24T11:45:14.951031800Z Wake Time: ?2015?-?08?-?24T13:39:03.667374500Z Wake Source: Power Button Event[916]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:04:01.737 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[917]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:04:01.738 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[918]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T10:08:30.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?24T14:08:30.500000000Z from ?2015?-?08?-?24T14:04:03.028471100Z. Change Reason: System time synchronized with the hardware clock. Event[919]: Log Name: System Source: BROWSER Date: 2015-08-24T10:08:31.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[920]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-24T10:08:36.769 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?24T14:03:59.886042100Z Wake Time: ?2015?-?08?-?24T14:08:31.739715100Z Wake Source: Power Button Event[921]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:16:24.411 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[922]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:16:24.420 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[923]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T10:25:24.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?24T14:25:24.500000000Z from ?2015?-?08?-?24T14:16:25.812329500Z. Change Reason: System time synchronized with the hardware clock. Event[924]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-24T10:25:29.404 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?24T14:16:22.850075800Z Wake Time: ?2015?-?08?-?24T14:25:25.599716900Z Wake Source: Power Button Event[925]: Log Name: System Source: Microsoft-Windows-DNS-Client Date: 2015-08-24T10:27:34.480 Event ID: 1014 Task: N/A Level: Warning Opcode: Info Keyword: N/A User: S-1-5-20 User Name: NT AUTHORITY\NETWORK SERVICE Computer: Surveillance1 Description: Name resolution for the name ci.bangor.mi.us timed out after none of the configured DNS servers responded. Event[926]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:48:36.261 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[927]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T10:48:36.263 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[928]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T15:19:45.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?24T19:19:45.500000000Z from ?2015?-?08?-?24T14:48:37.576294300Z. Change Reason: System time synchronized with the hardware clock. Event[929]: Log Name: System Source: BROWSER Date: 2015-08-24T15:19:46.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[930]: Log Name: System Source: EventLog Date: 2015-08-24T15:19:46.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 70743 seconds. Event[931]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-24T15:19:53.764 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?24T14:48:34.293017100Z Wake Time: ?2015?-?08?-?24T19:19:46.699889700Z Wake Source: Power Button Event[932]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-24T15:19:58.330 Event ID: 10010 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The server App.AppXy9rh3t8m2jfpvhhxp6y2ksgeq77vymbq.mca did not register with DCOM within the required timeout. Event[933]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-24T15:20:00.275 Event ID: 20003 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management has concluded the process to add Service usbser for Device Instance ID USB\VID_1004&PID_6000\6&2BC2CA&0&3 with the following status: 0. Event[934]: Log Name: System Source: Microsoft-Windows-UserPnp Date: 2015-08-24T15:20:00.618 Event ID: 20001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Driver Management concluded the process to install driver usbser.inf_x86_a8077066161f8bba\usbser.inf for Device Instance ID USB\VID_1004&PID_6000\6&2BC2CA&0&3 with the following status: 0x0. Event[935]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T17:38:30.744 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?24T21:38:30.486676800Z. Event[936]: Log Name: System Source: EventLog Date: 2015-08-24T17:38:46.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 3:45:12 PM on ?8/?24/?2015 was unexpected. Event[937]: Log Name: System Source: EventLog Date: 2015-08-24T17:38:46.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[938]: Log Name: System Source: EventLog Date: 2015-08-24T17:38:46.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[939]: Log Name: System Source: EventLog Date: 2015-08-24T17:38:46.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 16 seconds. Event[940]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.744 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[941]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.744 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[942]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.744 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was true. The last boot's success status was true. Event[943]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.744 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[944]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.744 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[945]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.745 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[946]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T17:38:30.745 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[947]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:32.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[948]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:32.221 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[949]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:32.222 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[950]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-24T17:38:36.224 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[951]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:36.688 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[952]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:36.779 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[953]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T17:38:36.792 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[954]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T17:38:36.792 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[955]: Log Name: System Source: HECI Date: 2015-08-24T17:38:39.754 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[956]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T17:38:40.648 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[957]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T17:38:40.649 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[958]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T17:38:40.650 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[959]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T17:38:40.755 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[960]: Log Name: System Source: rt640x86 Date: 2015-08-24T17:38:43.008 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[961]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:46.801 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[962]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T17:38:46.815 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[963]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-24T17:38:48.375 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[964]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-24T17:38:49.537 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[965]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:50.440 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[966]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:50.444 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[967]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:51.990 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[968]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.005 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[969]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.010 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[970]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.012 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[971]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.034 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[972]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.036 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[973]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.042 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[974]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.045 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[975]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.055 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[976]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.063 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[977]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.092 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[978]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.109 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[979]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.130 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[980]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.131 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[981]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.140 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[982]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.147 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[983]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.157 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[984]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:52.165 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[985]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-24T17:38:52.220 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[986]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-24T17:38:57.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[987]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.419 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[988]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.422 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[989]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.449 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[990]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.452 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[991]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.625 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[992]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T17:38:58.641 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[993]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:38:59.451 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[994]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-24T17:39:07.422 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[995]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:39:28.240 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[996]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:39:28.240 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[997]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:39:28.240 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[998]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:39:28.240 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[999]: Log Name: System Source: Service Control Manager Date: 2015-08-24T17:39:28.255 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[1000]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T17:42:37.902 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1001]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T17:43:01.094 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.415.0) Event[1002]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-24T17:43:15.763 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.415.0) Event[1003]: Log Name: System Source: Microsoft-Windows-DistributedCOM Date: 2015-08-24T17:54:45.739 Event ID: 10016 Task: N/A Level: Error Opcode: Info Keyword: Classic User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Event[1004]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-24T20:06:01.745 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?25T00:06:01.486417200Z. Event[1005]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T20:06:01.745 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[1006]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T20:06:01.745 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[1007]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T20:06:01.745 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[1008]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T20:06:01.746 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[1009]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-24T20:06:01.746 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[1010]: Log Name: System Source: EventLog Date: 2015-08-24T20:06:19.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 5:38:46 PM on ?8/?24/?2015 was unexpected. Event[1011]: Log Name: System Source: EventLog Date: 2015-08-24T20:06:19.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[1012]: Log Name: System Source: EventLog Date: 2015-08-24T20:06:19.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[1013]: Log Name: System Source: EventLog Date: 2015-08-24T20:06:19.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 17 seconds. Event[1014]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:03.204 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[1015]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:03.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[1016]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:03.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[1017]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-24T20:06:08.059 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[1018]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:08.241 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[1019]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:08.344 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[1020]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T20:06:08.356 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[1021]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T20:06:08.357 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[1022]: Log Name: System Source: HECI Date: 2015-08-24T20:06:09.566 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[1023]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T20:06:12.054 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1024]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T20:06:12.099 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1025]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T20:06:12.145 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1026]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-24T20:06:12.189 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1027]: Log Name: System Source: rt640x86 Date: 2015-08-24T20:06:14.337 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[1028]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:18.738 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[1029]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-24T20:06:18.741 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[1030]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-24T20:06:19.117 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[1031]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-24T20:06:19.186 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[1032]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:26.572 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[1033]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:26.576 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1034]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.599 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1035]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.714 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1036]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.720 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1037]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.723 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1038]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.755 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1039]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.757 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[1040]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.767 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[1041]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.770 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1042]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.844 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1043]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:27.852 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[1044]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.848 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[1045]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.865 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[1046]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.888 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[1047]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.889 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1048]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.899 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[1049]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.906 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1050]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:28.916 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1051]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-24T20:06:29.093 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[1052]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:06:29.674 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[1053]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:29.942 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1054]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-24T20:06:33.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[1055]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.024 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1056]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.027 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1057]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.051 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1058]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.053 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1059]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.342 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1060]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-24T20:06:39.360 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1061]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:07:04.190 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[1062]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:07:04.190 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[1063]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-24T20:07:05.512 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[1064]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:07:06.300 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[1065]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:07:06.300 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[1066]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:07:06.315 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[1067]: Log Name: System Source: User32 Date: 2015-08-24T20:28:44.772 Event ID: 1074 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The process C:\Windows\System32\RuntimeBroker.exe (SURVEILLANCE1) has initiated the power off of computer SURVEILLANCE1 on behalf of user Surveillance1\Surveillance for the following reason: Other (Unplanned) Reason Code: 0x0 Shutdown Type: power off Comment: Event[1068]: Log Name: System Source: Service Control Manager Date: 2015-08-24T20:28:45.335 Event ID: 7031 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Sync Host_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service. Event[1069]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-24T20:28:48.181 Event ID: 7002 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logoff Notification for Customer Experience Improvement Program Event[1070]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T20:28:50.567 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[1071]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-24T20:28:50.569 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[1072]: Log Name: System Source: BROWSER Date: 2015-08-25T05:33:25.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[1073]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T05:33:24.499 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?25T09:33:24.500000000Z from ?2015?-?08?-?25T00:28:53.432806000Z. Change Reason: System time synchronized with the hardware clock. Event[1074]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-25T05:33:30.759 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?25T09:33:29.526933700Z Wake Time: ?2015?-?08?-?25T09:33:25.611671500Z Wake Source: Power Button Event[1075]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T05:33:33.286 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Application API Event[1076]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T05:34:19.488 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?25T09:34:19.500000000Z from ?2015?-?08?-?25T09:33:35.538804900Z. Change Reason: System time synchronized with the hardware clock. Event[1077]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T05:34:20.156 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[1078]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T05:34:20.156 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The boot type was 0x1. Event[1079]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T05:34:20.156 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[1080]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T05:34:20.156 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[1081]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-25T05:34:23.565 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?25T09:33:29.526933700Z Wake Time: ?2015?-?08?-?25T09:34:20.157959300Z Wake Source: Unknown Event[1082]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-25T05:34:26.338 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[1083]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T06:08:02.397 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[1084]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T06:08:02.420 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[1085]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T09:26:27.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?25T13:26:27.500000000Z from ?2015?-?08?-?25T10:08:04.035901400Z. Change Reason: System time synchronized with the hardware clock. Event[1086]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-25T09:26:34.545 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?25T10:08:00.009789800Z Wake Time: ?2015?-?08?-?25T13:26:28.712182300Z Wake Source: Power Button Event[1087]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T09:51:36.505 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[1088]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T09:51:36.507 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[1089]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T10:00:14.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?25T14:00:14.500000000Z from ?2015?-?08?-?25T13:51:37.839689300Z. Change Reason: System time synchronized with the hardware clock. Event[1090]: Log Name: System Source: BROWSER Date: 2015-08-25T10:00:15.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[1091]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-25T10:00:20.729 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?25T13:51:35.202598100Z Wake Time: ?2015?-?08?-?25T14:00:19.179683800Z Wake Source: Power Button Event[1092]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T11:08:28.745 Event ID: 12 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The operating system started at system time ?2015?-?08?-?25T15:08:28.486580800Z. Event[1093]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T11:08:28.746 Event ID: 20 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The last shutdown's success status was false. The last boot's success status was true. Event[1094]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T11:08:28.746 Event ID: 27 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot type was 0x0. Event[1095]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T11:08:28.746 Event ID: 25 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The boot menu policy was 0x1. Event[1096]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T11:08:28.746 Event ID: 18 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: There are 0x1 boot options on this system. Event[1097]: Log Name: System Source: Microsoft-Windows-Kernel-Boot Date: 2015-08-25T11:08:28.746 Event ID: 32 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The bootmgr spent 0 ms waiting for user input. Event[1098]: Log Name: System Source: EventLog Date: 2015-08-25T11:08:45.000 Event ID: 6008 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The previous system shutdown at 9:49:57 AM on ?8/?25/?2015 was unexpected. Event[1099]: Log Name: System Source: EventLog Date: 2015-08-25T11:08:45.000 Event ID: 6009 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Microsoft (R) Windows (R) 10.00. 10240 Multiprocessor Free. Event[1100]: Log Name: System Source: EventLog Date: 2015-08-25T11:08:45.000 Event ID: 6005 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Event log service was started. Event[1101]: Log Name: System Source: EventLog Date: 2015-08-25T11:08:45.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 16 seconds. Event[1102]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:30.204 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileInfo' (10.0, ?2015?-?07?-?09T23:25:07.000000000Z) has successfully loaded and registered with Filter Manager. Event[1103]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:30.205 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'Wof' (10.0, ?2015?-?08?-?05T21:53:05.000000000Z) has successfully loaded and registered with Filter Manager. Event[1104]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:30.206 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'WdFilter' (10.0, ?2015?-?07?-?09T23:29:44.000000000Z) has successfully loaded and registered with Filter Manager. Event[1105]: Log Name: System Source: Microsoft-Windows-Ntfs Date: 2015-08-25T11:08:33.262 Event ID: 98 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Volume C: (\Device\HarddiskVolume1) is healthy. No action is needed. Event[1106]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:34.065 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'FileCrypt' (10.0, ?2015?-?07?-?09T23:25:29.000000000Z) has successfully loaded and registered with Filter Manager. Event[1107]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:34.354 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'npsvctrig' (10.0, ?2015?-?07?-?09T23:24:54.000000000Z) has successfully loaded and registered with Filter Manager. Event[1108]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T11:08:34.504 Event ID: 41 Task: N/A Level: Critical Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: The system has rebooted without cleanly shutting down first. This error could be caused if the system stopped responding, crashed, or lost power unexpectedly. Event[1109]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T11:08:34.505 Event ID: 508 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system has been constrained to a periodic tick Reason: Errata Manager override. Event[1110]: Log Name: System Source: HECI Date: 2015-08-25T11:08:35.535 Event ID: 2 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Intel(R) Management Engine Interface driver has started successfully. Event[1111]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-25T11:08:36.491 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 0 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1112]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-25T11:08:36.495 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 1 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1113]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-25T11:08:36.496 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 2 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1114]: Log Name: System Source: Microsoft-Windows-Kernel-Processor-Power Date: 2015-08-25T11:08:36.497 Event ID: 55 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Processor 3 in group 0 exposes the following power management capabilities: Idle state type: ACPI Idle (C) States (3 state(s)) Performance state type: ACPI Performance (P) / Throttle (T) States Nominal Frequency (MHz): 2261 Maximum performance percentage: 100 Minimum performance percentage: 41 Minimum throttle percentage: 5 Event[1115]: Log Name: System Source: rt640x86 Date: 2015-08-25T11:08:38.673 Event ID: 1 Task: N/A Level: Warning Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: Realtek PCIe GBE Family Controller is disconnected from network. Event[1116]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:44.934 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'storqosflt' (10.0, ?2015?-?07?-?09T23:28:02.000000000Z) has successfully loaded and registered with Filter Manager. Event[1117]: Log Name: System Source: Microsoft-Windows-FilterManager Date: 2015-08-25T11:08:44.946 Event ID: 6 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: File System Filter 'luafv' (10.0, ?2015?-?07?-?09T23:24:53.000000000Z) has successfully loaded and registered with Filter Manager. Event[1118]: Log Name: System Source: Microsoft-Windows-Dhcp-Client Date: 2015-08-25T11:08:45.044 Event ID: 50036 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv4 client service is started Event[1119]: Log Name: System Source: Microsoft-Windows-DHCPv6-Client Date: 2015-08-25T11:08:46.832 Event ID: 51046 Task: Service State Event Level: Information Opcode: ServiceStart Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: DHCPv6 client service is started Event[1120]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:49.171 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RecordingRestart definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[1121]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:49.173 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\DispatchRecoveryTasks definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1122]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.656 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ActivateWindowsSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1123]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.666 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW2 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1124]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.669 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\MediaCenterRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1125]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.671 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURActivate definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1126]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.687 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrScheduleTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1127]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.689 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Processor definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[1128]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.693 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PeriodicScanRetry definition. Additional Data: Error Value: %windir%\ehome\MCUpdate.exe. Event[1129]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.695 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ehDRMInit definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1130]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.701 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ReindexSearchRoot definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1131]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.706 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton WSC Integration definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\WSCStub.exe. Event[1132]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.712 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Norton Security Suite\Norton Error Analyzer definition. Additional Data: Error Value: C:\Program Files\Norton Security Suite\Engine\21.1.0.18\SymErr.exe. Event[1133]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.756 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[1134]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.786 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\mcupdate_scheduled definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate. Event[1135]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.787 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1136]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.794 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\StartRecording definition. Additional Data: Error Value: %SystemRoot%\ehome\ehrec. Event[1137]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.801 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\RegisterSearch definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1138]: Log Name: System Source: Microsoft-Windows-WLAN-AutoConfig Date: 2015-08-25T11:08:50.811 Event ID: 4000 Task: N/A Level: Information Opcode: Start Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: WLAN AutoConfig service has successfully started. Event[1139]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.818 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\ConfigureInternetTimeService definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1140]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:50.828 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\OCURDiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1141]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:08:52.086 Event ID: 7001 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Tcp Listener Adapter service depends on the Net.Tcp Port Sharing Service service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Event[1142]: Log Name: System Source: Microsoft-Windows-WAS Date: 2015-08-25T11:08:54.000 Event ID: 5211 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Windows Process Activation Service (WAS) started with 'Classic' mode using 'ConfigurationSystem' Event[1143]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:56.819 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PvrRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1144]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:56.823 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\UpdateRecordPath definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1145]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:56.847 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\SqlLiteRecoveryTask definition. Additional Data: Error Value: %SystemRoot%\ehome\mcupdate.exe. Event[1146]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:56.849 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\InstallPlayReady definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1147]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:57.706 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscovery definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1148]: Log Name: System Source: Microsoft-Windows-TaskScheduler Date: 2015-08-25T11:08:57.722 Event ID: 414 Task: Task Misconfiguration Level: Warning Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Task Scheduler service found a misconfiguration in the NT TASK\Microsoft\Windows\Media Center\PBDADiscoveryW1 definition. Additional Data: Error Value: %SystemRoot%\ehome\ehPrivJob.exe. Event[1149]: Log Name: System Source: Microsoft-Windows-Winlogon Date: 2015-08-25T11:09:09.333 Event ID: 7001 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: User Logon Notification for Customer Experience Improvement Program Event[1150]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:09:25.335 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Pipe Listener Adapter service to connect. Event[1151]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:09:25.335 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Pipe Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[1152]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:09:26.506 Event ID: 7009 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: A timeout was reached (30000 milliseconds) while waiting for the Net.Msmq Listener Adapter service to connect. Event[1153]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:09:26.506 Event ID: 7000 Task: N/A Level: Error Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The Net.Msmq Listener Adapter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Event[1154]: Log Name: System Source: Service Control Manager Date: 2015-08-25T11:09:26.522 Event ID: 7026 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The following boot-start or system-start driver(s) did not load: dam Event[1155]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T11:12:36.283 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1156]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T11:13:46.013 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.518.0) Event[1157]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T11:14:06.984 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Definition Update for Windows Defender - KB2267602 (Definition 1.205.518.0) Event[1158]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T11:49:14.872 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDScan for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Scanner stopped the power transition. Event[1159]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T11:49:14.872 Event ID: 40 Task: N/A Level: Information Opcode: N/A Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The driver \Driver\WSDPrintDevice for device SWD\DAFWSDProvider\urn:uuid:00000000-0000-1000-8000-60128b4068b3/http://schemas.canon.com/Printer stopped the power transition. Event[1160]: Log Name: System Source: Microsoft-Windows-Kernel-Power Date: 2015-08-25T11:49:14.886 Event ID: 42 Task: N/A Level: Information Opcode: Info Keyword: N/A User: N/A User Name: N/A Computer: Surveillance1 Description: The system is entering sleep. Sleep Reason: Button or Lid Event[1161]: Log Name: System Source: EventLog Date: 2015-08-25T15:09:20.000 Event ID: 6013 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The system uptime is 14451 seconds. Event[1162]: Log Name: System Source: BROWSER Date: 2015-08-25T15:09:20.000 Event ID: 8033 Task: N/A Level: Information Opcode: N/A Keyword: Classic User: N/A User Name: N/A Computer: Surveillance1 Description: The browser has forced an election on network \Device\NetBT_Tcpip_{BDE189B0-4A0B-4283-ACE1-539B0F5F6225} because a master browser was stopped. Event[1163]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T15:09:19.500 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: Time User: N/A User Name: N/A Computer: Surveillance1 Description: The system time has changed to ?2015?-?08?-?25T19:09:19.500000000Z from ?2015?-?08?-?25T15:49:16.571625400Z. Change Reason: System time synchronized with the hardware clock. Event[1164]: Log Name: System Source: Microsoft-Windows-Power-Troubleshooter Date: 2015-08-25T15:09:26.980 Event ID: 1 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-19 User Name: NT AUTHORITY\LOCAL SERVICE Computer: Surveillance1 Description: The system has returned from a low power state. Sleep Time: ?2015?-?08?-?25T15:49:04.873702800Z Wake Time: ?2015?-?08?-?25T19:09:20.682514400Z Wake Source: Power Button Event[1165]: Log Name: System Source: Microsoft-Windows-DNS-Client Date: 2015-08-25T15:09:27.210 Event ID: 1014 Task: N/A Level: Warning Opcode: Info Keyword: N/A User: S-1-5-20 User Name: NT AUTHORITY\NETWORK SERVICE Computer: Surveillance1 Description: Name resolution for the name wpad timed out after none of the configured DNS servers responded. Event[1166]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:13:22.133 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1167]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:13:22.133 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1168]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:13:24.855 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1169]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:13.194 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Camera Event[1170]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T15:14:14.368 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCamera_8wekyb3d8bbwe\Microsoft.WindowsCamera_5.49.3004.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[1171]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T15:14:20.196 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsCalculator_8wekyb3d8bbwe\Microsoft.WindowsCalculator_10.1508.14010.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[1172]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:25.168 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Camera Event[1173]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:25.168 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Calculator Event[1174]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:27.493 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Calculator Event[1175]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:27.493 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Windows Maps Event[1176]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:14:27.493 Event ID: 44 Task: Windows Update Agent Level: Information Opcode: Download Keyword: Download,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Windows Update started downloading an update. Event[1177]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T15:14:51.426 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.WindowsMaps_8wekyb3d8bbwe\Microsoft.WindowsMaps_4.1507.50821.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[1178]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:15:03.305 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Windows Maps Event[1179]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:15:16.303 Event ID: 43 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Started User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Started: Windows has started installing the following update: Microsoft Photos Event[1180]: Log Name: System Source: Microsoft-Windows-Kernel-General Date: 2015-08-25T15:15:18.819 Event ID: 16 Task: N/A Level: Information Opcode: Info Keyword: N/A User: S-1-5-21-3938444892-375232425-1508535582-1000 User Name: Surveillance1\Surveillance Computer: Surveillance1 Description: The access history in hive \??\C:\Users\Surveillance\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Microsoft.Windows.Photos_15.820.12440.0_x86__8wekyb3d8bbwe\ActivationStore\ActivationStore.dat was cleared updating 0 keys and creating 0 modified pages. Event[1181]: Log Name: System Source: Microsoft-Windows-WindowsUpdateClient Date: 2015-08-25T15:15:26.685 Event ID: 19 Task: Windows Update Agent Level: Information Opcode: Installation Keyword: Installation,Success User: S-1-5-18 User Name: NT AUTHORITY\SYSTEM Computer: Surveillance1 Description: Installation Successful: Windows successfully installed the following update: Microsoft Photos