我把登陆的那人的信息发过来,大牛们去K他
日志名称: Security
来源: Microsoft-Windows-Security-Auditing
日期: 2011/2/11 16:25:23
事件 ID: 5056
任务类别: 系统完整性
级别: 信息
关键字: 审核成功
用户: 暂缺
计算机: lenovo-PC
描述:
已执行加密自检。
主题:
安全 ID: SYSTEM
帐户名称: LENOVO-PC$
帐户域: WORKGROUP
登录 ID: 0x3e7
模块: ncrypt.dll
返回代码: 0x0
事件 Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>5056</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2011-02-11T08:25:23.635865000Z" />
<EventRecordID>935</EventRecordID>
<Correlation />
<Execution ProcessID="808" ThreadID="880" />
<Channel>Security</Channel>
<Computer>lenovo-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">LENOVO-PC$</Data>
<Data Name="SubjectDomainName">WORKGROUP</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="Module">ncrypt.dll</Data>
<Data Name="ReturnCode">0x0</Data>
</EventData>
</Event>
日志名称: Security
来源: Microsoft-Windows-Security-Auditing
日期: 2011/2/11 16:25:22
事件 ID: 4672
任务类别: 特殊登录
级别: 信息
关键字: 审核成功
用户: 暂缺
计算机: lenovo-PC
描述:
为新登录分配了特殊权限。
主题:
安全 ID: SYSTEM
帐户名: SYSTEM
帐户域: NT AUTHORITY
登录 ID: 0x3e7
特权: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
事件 Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4672</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12548</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2011-02-11T08:25:22.434854300Z" />
<EventRecordID>934</EventRecordID>
<Correlation />
<Execution ProcessID="808" ThreadID="1220" />
<Channel>Security</Channel>
<Computer>lenovo-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">SYSTEM</Data>
<Data Name="SubjectDomainName">NT AUTHORITY</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege</Data>
</EventData>
</Event>