a ješte 2:
- System
- Provider
[ Name] Service Control Manager
[ Guid] {555908d1-a6d7-4695-8e1e-26931d2012f4}
[ EventSourceName] Service Control Manager
- EventID 7032
[ Qualifiers] 49152
Version 0
Level 2
Task 0
Opcode 0
Keywords 0x8080000000000000
- TimeCreated
[ SystemTime] 2014-12-13T20:02:11.911433500Z
EventRecordID 6980
Correlation
- Execution
[ ProcessID] 668
[ ThreadID] 6324
Channel System
Computer WIN-TPNT9UMJUTD
Security
- EventData
param1 1
param2 Restart the service
param3 DHCP Client
param4 %%1056
- System
- Provider
[ Name] Microsoft-Windows-DistributedCOM
[ Guid] {1B562E86-B7AA-4131-BADC-B6F3A001407E}
[ EventSourceName] DCOM
- EventID 10016
[ Qualifiers] 0
Version 0
Level 2
Task 0
Opcode 0
Keywords 0x8080000000000000
- TimeCreated
[ SystemTime] 2014-12-12T16:27:01.136060700Z
EventRecordID 6707
Correlation
- Execution
[ ProcessID] 844
[ ThreadID] 2340
Channel System
Computer WIN-TPNT9UMJUTD
- Security
[ UserID] S-1-5-19
- EventData
param1 machine-default
param2 Local
param3 Activation
param4 {C2F03A33-21F5-47FA-B4BB-156362A2F239}
param5 {316CDED5-E4AE-4B15-9113-7055D84DCC97}
param6 NT AUTHORITY
param7 LOCAL SERVICE
param8 S-1-5-19
param9 LocalHost (Using LRPC)
param10 Unavailable
param11 Unavailable