1. zamrznutí
- System
- Provider
[ Name] EventLog
- EventID 6008
[ Qualifiers] 32768
Level 2
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2015-11-05T14:49:18.000000000Z
EventRecordID 20124
Channel System
Computer Simon-HP
Security
- EventData
15:43:44
05.11.2015
121666
DF070B00040005000F002B002C000603DF070B00040005000E002B002C0006033C0000003C000000000000000000000000000000000000000100000000000000
--------------------------------------------------------------------------------
Binární data:
Ve slovech
0000: 000B07DF 00050004 002B000F 0306002C
0010: 000B07DF 00050004 002B000E 0306002C
0020: 0000003C 0000003C 00000000 00000000
0030: 00000000 00000000 00000001 00000000
V bajtech
0000: DF 07 0B 00 04 00 05 00 ß.......
0008: 0F 00 2B 00 2C 00 06 03 ..+.,...
0010: DF 07 0B 00 04 00 05 00 ß.......
0018: 0E 00 2B 00 2C 00 06 03 ..+.,...
0020: 3C 00 00 00 3C 00 00 00 <...<...
0028: 00 00 00 00 00 00 00 00 ........
0030: 00 00 00 00 00 00 00 00 ........
0038: 01 00 00 00 00 00 00 00 ........
Dodatečně přidáno po 21 vteřinách:
- <Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2015-11-05T14:49:18.000000000Z" />
<EventRecordID>20124</EventRecordID>
<Channel>System</Channel>
<Computer>Simon-HP</Computer>
<Security />
</System>
- <EventData>
<Data>15:43:44</Data>
<Data>05.11.2015</Data>
<Data />
<Data />
<Data>121666</Data>
<Data />
<Data />
<Binary>DF070B00040005000F002B002C000603DF070B00040005000E002B002C0006033C0000003C000000000000000000000000000000000000000100000000000000</Binary>
</EventData>
</Event>
Dodatečně přidáno po 1 minutě 44 vteřinách:
- System
- Provider
[ Name] Microsoft-Windows-Kernel-Power
[ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4}
EventID 41
Version 3
Level 1
Task 63
Opcode 0
Keywords 0x8000200000000002
- TimeCreated
[ SystemTime] 2015-11-05T14:48:46.932864700Z
EventRecordID 20133
Correlation
- Execution
[ ProcessID] 4
[ ThreadID] 8
Channel System
Computer Simon-HP
- Security
[ UserID] S-1-5-18
- EventData
BugcheckCode 0
BugcheckParameter1 0x0
BugcheckParameter2 0x0
BugcheckParameter3 0x0
BugcheckParameter4 0x0
SleepInProgress 0
PowerButtonTimestamp 0
BootAppStatus 0
Dodatečně přidáno po 2 minutách 28 vteřinách:
- <Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>3</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000200000000002</Keywords>
<TimeCreated SystemTime="2015-11-05T14:48:46.932864700Z" />
<EventRecordID>20133</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Simon-HP</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
</EventData>
</Event>
Dodatečně přidáno po 4 minutách 20 vteřinách:
2. Zamrznutí
- System
- Provider
[ Name] EventLog
- EventID 6008
[ Qualifiers] 32768
Level 2
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2015-11-05T16:50:26.000000000Z
EventRecordID 20167
Channel System
Computer Simon-HP
Security
- EventData
17:38:19
05.11.2015
6584
DF070B00040005001100260013008A01DF070B00040005001000260013008A013C0000003C000000000000000000000000000000000000000100000000000000
--------------------------------------------------------------------------------
Binární data:
Ve slovech
0000: 000B07DF 00050004 00260011 018A0013
0010: 000B07DF 00050004 00260010 018A0013
0020: 0000003C 0000003C 00000000 00000000
0030: 00000000 00000000 00000001 00000000
V bajtech
0000: DF 07 0B 00 04 00 05 00 ß.......
0008: 11 00 26 00 13 00 8A 01 ..&....
0010: DF 07 0B 00 04 00 05 00 ß.......
0018: 10 00 26 00 13 00 8A 01 ..&....
0020: 3C 00 00 00 3C 00 00 00 <...<...
0028: 00 00 00 00 00 00 00 00 ........
0030: 00 00 00 00 00 00 00 00 ........
0038: 01 00 00 00 00 00 00 00 ........
Dodatečně přidáno po 4 minutách 56 vteřinách:
- <Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="EventLog" />
<EventID Qualifiers="32768">6008</EventID>
<Level>2</Level>
<Task>0</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2015-11-05T16:50:26.000000000Z" />
<EventRecordID>20167</EventRecordID>
<Channel>System</Channel>
<Computer>Simon-HP</Computer>
<Security />
</System>
- <EventData>
<Data>17:38:19</Data>
<Data>05.11.2015</Data>
<Data />
<Data />
<Data>6584</Data>
<Data />
<Data />
<Binary>DF070B00040005001100260013008A01DF070B00040005001000260013008A013C0000003C000000000000000000000000000000000000000100000000000000</Binary>
</EventData>
</Event>
Dodatečně přidáno po 5 minutách 44 vteřinách:
- System
- Provider
[ Name] Microsoft-Windows-Kernel-Power
[ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4}
EventID 41
Version 3
Level 1
Task 63
Opcode 0
Keywords 0x8000200000000002
- TimeCreated
[ SystemTime] 2015-11-05T16:50:05.775498000Z
EventRecordID 20178
Correlation
- Execution
[ ProcessID] 4
[ ThreadID] 8
Channel System
Computer Simon-HP
- Security
[ UserID] S-1-5-18
- EventData
BugcheckCode 0
BugcheckParameter1 0x0
BugcheckParameter2 0x0
BugcheckParameter3 0x0
BugcheckParameter4 0x0
SleepInProgress 0
PowerButtonTimestamp 0
BootAppStatus 0
Dodatečně přidáno po 5 minutách 59 vteřinách:
- <Event xmlns="
http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-Power" Guid="{331C3B3A-2005-44C2-AC5E-77220C37D6B4}" />
<EventID>41</EventID>
<Version>3</Version>
<Level>1</Level>
<Task>63</Task>
<Opcode>0</Opcode>
<Keywords>0x8000200000000002</Keywords>
<TimeCreated SystemTime="2015-11-05T16:50:05.775498000Z" />
<EventRecordID>20178</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>Simon-HP</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="BugcheckCode">0</Data>
<Data Name="BugcheckParameter1">0x0</Data>
<Data Name="BugcheckParameter2">0x0</Data>
<Data Name="BugcheckParameter3">0x0</Data>
<Data Name="BugcheckParameter4">0x0</Data>
<Data Name="SleepInProgress">0</Data>
<Data Name="PowerButtonTimestamp">0</Data>
<Data Name="BootAppStatus">0</Data>
</EventData>
</Event>