ElfFile;8=ElfChnk::(e@f"R= t?FM+&HP%.I GE' *"1$G4**vb'm &=u [SAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemA2{ProviderF=KNameService Control ManagerF)Guid&{555908d1-a6d7-4695-8e1e-26931d2012f4}`EventSourceNameService Control ManagerAMSaEventID't) Qualifiers " Version dLevelE{Task Opcode$?jKeywordsAPj; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\F ActivityIDFS5RelatedActivityIDAm ExecutionHF ProcessID9ThreadID .aChannelSystemV+j;nComputerWEDWARESET03.EWEDEL.LOCALAB.SecurityfLUserID ! :!|@u@tm0`" F% 4X4v*M^pD EventDataA5oData=param1 A#=param2  !Binary Windows Updatestoppedwuauserv/1** !m & u!|@vb'm0G# F% 4X"Remote Registrystopped"RemoteRegistry/1ra ** !m . .)<&> AMsj5http://schemas.microsoft.com/win/2004/08/events/eventvAF=AS t      ?Aj   AFF AF  <+WEDWARESET03.EWEDEL.LOCALA  ! @ ! !mP7$ F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ GɓrTb[xA5'=MiniportNameLen A/!= MiniportName B!Microsoft Hyper-V Network Adapter **`!m .  @ a! !mP7% F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ B!Microsoft Hyper-V Network Adapter`**`c%m .  @ a!!mP7& F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ B!Microsoft Hyper-V Network Adapter`**2m .   @ !c%m\%' F%Microsoft-Windows-Kernel-GeneralOצ]System wXwӓMuWA%=NewTime A%=OldTime A#=Reason %mm**` c=m & !|@2m0t<( F% 4XP,WinHTTP Web Proxy Auto-Discovery Servicestopped,WinHttpAutoProxySvc/1`** om .   @ ! c=m) F%Microsoft-Windows-Kernel-GeneralOצ]System /w/wmUWF~rA/!= MajorVersion A/!= MinorVersion A/!= BuildVersion A+= QfeVersion A3%=ServiceVersion A'=BootMode A)= StartTime %RLm**p om UU",6&MAMsj5http://schemas.microsoft.com/win/2004/08/events/event#A"=EventLogAS t   ?Aj   System<+WEDWARESET03.EWEDEL.LOCALA  ! !x om* F% FHF%g>9{p(4(  D@17:19:21 2020- 08- 08271335@<<p** om U o!y om+ F% FHL6.03.9600Multiprocessor Free18910** om U ;!u om, F% FH'** c=m U !} om- F% FHZ7060-60 Central European Standard Time1.10Windows Server 2012 R2 Standard6.3.9600 Build 9600 Multiprocessor Free9600.winblue_ltsb_escrow.191014-170057fe20daNot AvailableNot Available91248894415WEDWARESET03.EWEDEL.LOCAL** c=m .   : ! c=m. F%Microsoft-Windows-Kernel-BootDzMK ^SSystem җ) җ)藭C9DizA7)=LastShutdownGood A/!= LastBootGood    **x c=m .   : s! c=m/ F%Microsoft-Windows-Kernel-BootDzMK ^SSystem T"T;hX<͚8J@4A'=BootType x**x c=m .   : w! c=m0 F%Microsoft-Windows-Kernel-BootDzMK ^SSystem n1$neO@3D8A+= EntryCount x**:Rm .   : ! c=m1 F%Microsoft-Windows-Kernel-BootDzMK ^SSystem v %v ?M(\PAC5=BitlockerUserInputTime  **m .   > !:Rm2 F%Microsoft-Windows-FilterManagercIİSystem w7E' w7->vSZGsl`A-= FinalStatus A;-=DeviceVersionMajor A;-=DeviceVersionMinor A7)=DeviceNameLength A+= DeviceName A+= DeviceTime  file_tracker"** ym .   , )!bmh3 F%Microsoft-Windows-Ntfsz?nMĂSystem (*(حh@9 2A)= DriveName A+= DeviceName AA3=CorruptionActionState .C:\Device\HarddiskVolume4 **X+ m .   > M!ym4 F%Microsoft-Windows-FilterManagercIİSystem w7E'  eamonm&مPX**X2m .   > S!+ m5 F%Microsoft-Windows-FilterManagercIİSystem w7E' npsvctrig[~<X**֐Ym .   < !?)2m6 F%Microsoft-Windows-Kernel-Power:;3 D^w" 7ִSystem m.m@$)M5 A/!= BugcheckCode A;-=BugcheckParameter1 A;-=BugcheckParameter2 A;-=BugcheckParameter3 A;-=BugcheckParameter4 A5'=SleepInProgress A?1=PowerButtonTimestamp  A1#= BootAppStatus  **^m .   , !b֐Ym7 F%Microsoft-Windows-Ntfsz?nMĂSystem (*`.\\?\Volume{3fd00a6c-51d9-4bf0-ad5e-957d55faae2e}\Device\HarddiskVolume1**^m .   P !/7^mh8 F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4ewykǟT3B- XLA!=Group A#=Number A3%=IdleStateCount A;-=IdleImplementation A7)=NominalFrequency AI;=MaximumPerformancePercent AI;=MinimumPerformancePercent AC5=MinimumThrottlePercent AI;=PerformanceImplementation  % ddd**p^m .   P V!/7^mh9 F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh: F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh; F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh< F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh= F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh> F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh? F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p^m .   P V!/7^mh@ F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4 % dddp**p ^m .   P V!/7^mhA F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4  % dddp**p!^m .   P V!/7^mhB F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4  % dddp**p"$mm .   P V!/7^mhC F%Microsoft-Windows-Kernel-Processor-PowergQNo)H`'System ewG4  % dddp**#om .   @ !$mmLD F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem cGc ҳ\qeA+= VersionLen A%=Version A#=Status 5.0**p$qm .   @ c!omhE F%Microsoft-Windows-Kernel-GeneralOצ]System ܡ^Iܡ^KNA3%=HiveNameLength A'=HiveName A-= KeysUpdated A+= DirtyPages >\SystemRoot\System32\Config\SAMIp**`%qm .  @ a! qmF F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ B!Microsoft Hyper-V Network Adapter`**h&-m .   @ a!qmLG F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ B!Microsoft Hyper-V Network Adapterh**h',m .   @ a! -mHH F%Microsoft-Windows-Hyper-V-NetvscK/hOڤFOlSystem Gɓ B!Microsoft Hyper-V Network Adapterh**(Cm .   P !BB,mPTI F%Microsoft-Windows-Directory-Services-SAM O 'JIP^OحSystem \?P\?A͵buAS=%SAMMSG_RESTRICT_REMOTE_SAM_DEFAULT_SDA;-=Default SD String: **)h'm & e!|@CmHJ F% 4XPlug and PlayrunningPlugPlay/4***Mm & O!|@h'mHK F% 4X PowerrunningPower/4**0+Ɔm & !|@MmHL F% 4X8DCOM Server Process LauncherrunningDcomLaunch/40**(,Qm & y!|@ƆmHM F% 4X&RPC Endpoint MapperrunningRpcEptMapper/4(**(-Pm & {!|@QmHN F% 4X6Remote Procedure Call (RPC)runningRpcSs/4(**`.긗m & !|@PmHO F% 4XN.Background Tasks Infrastructure Servicerunning.BrokerInfrastructure/4`**/ Qm & k!|@긗mHP F% 4X* Local Session Managerrunning LSM/4**00fm & !|@ QmHQ F% 4X(*System Events Brokerrunning*SystemEventsBroker/40**P1Ԡ8m .   > K!fmxR F%Microsoft-Windows-FilterManagercIİSystem w7E' luafvKP**h2gim .   > ]!Ԡ8mxS F%Microsoft-Windows-FilterManagercIİSystem w7E'file_protector-h**`3e`m .   > Y!gimxT F%Microsoft-Windows-FilterManagercIİSystem w7E' virtual_file *`**4-m & [!|@e`mHU F% 4XESET Servicerunningekrn/4**52m & m!|@-mHV F% 4X"Windows Event LogrunningEventLog/4**6—m & S!|@2mHW F% 4X ThemesrunningThemes/4** 7=×m & s!|@—mHX F% 4X"COM+ Event SystemrunningEventSystem/4 ** 84!×m & q!|@=×mHY F% 4X(User Profile ServicerunningProfSvc/4 **094×m & !|@4!×mHZ F% 4XBSystem Event Notification ServicerunningSENS/40**:×m & k!|@4×mH[ F% 4X&Group Policy Clientrunninggpsvc/4610-3132531746-16064-1-5**%< .&  Nd!3@<XܽXܽd %Microsoft-Windows-AppXDeployment-Server9G?J]-CMicrosoft-Windows-AppXDeploymentServer/Operational ?EpXDe**&D( .&  Nds!2@D(tkkl8&Microsoft-Windows-AppXDeployment-Server9G?J]-CMicrosoft-Windows-AppXDeploymentServer/Operational  `S-1-5-21-1044025345-1348728610-3132531746-16064-21-44025345-134 .&  Nd1^