25.12.2014 Views

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

Analysis and Evaluation of the Windows Event Log - Bill Buchanan

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Ano<strong>the</strong>r check <strong>of</strong> <strong>the</strong> Services reveals that <strong>the</strong> <strong>Event</strong> Service has been stopped.<br />

And <strong>the</strong> <strong>Event</strong> Viewer produces <strong>the</strong> following error when trying to access it:<br />

We now have full control over <strong>the</strong> original ‘Sec<strong>Event</strong>.Evt’ file <strong>and</strong> as such it is replaced<br />

with <strong>the</strong> copy that was previously made.<br />

The original file is kept <strong>and</strong> renamed to ‘OldSec<strong>Event</strong>.Evt’, while ‘Copy <strong>of</strong><br />

Sec<strong>Event</strong>.Evt’ is renamed to replace its original.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!