msaudite.dll.mui 安全审核事件 DLL 181375e495ef7697b30a6077cf5ed2ce

File info

File name: msaudite.dll.mui
Size: 91648 byte
MD5: 181375e495ef7697b30a6077cf5ed2ce
SHA1: 4ed863f2d6adfa3f448a8e8d9b84c3a561a45e35
SHA256: ce197027cc6509657009a9a17e0c831bd9ccb1366c9ae8ddc03157e64c4d2e2d
Operating systems: Windows 10
Extension: MUI

Translations messages and strings

If an error occurred or the following message in Chinese (Simplified) language and you cannot find a solution, than check answer in English. Table below helps to know how correctly this phrase sounds in English.

id Chinese (Simplified) English
0x0没有使用的消息 ID Unused message ID
0x1系统事件 System Event
0x2登录/注销 Logon/Logoff
0x3对象访问 Object Access
0x4特权使用 Privilege Use
0x5详细追踪 Detailed Tracking
0x6策略改动 Policy Change
0x7帐户管理 Account Management
0x8目录服务访问 Directory Service Access
0x9帐户登录 Account Logon
0x200正在启动 Windows。 Windows is starting up.
0x201Windows 正在关机。所有的登录会话都会关闭。 Windows is shutting down.All logon sessions will be terminated by this shutdown.
0x202本地安全机制机构已加载身份验证数据包。这个身份验证数据包将用来验证登录操作。%n身份验证数据包名: %t%1 An authentication package has been loaded by the Local Security Authority.This authentication package will be used to authenticate logon attempts.%nAuthentication Package Name:%t%1
0x203受信任的登录过程已经在本地安全机制机构注册。将信任这个登录过程来提交登录申请。%n%n%t登录过程名:%t%1%n%t调用方用户名:%t%2%n%t调用方域:%t%3%n%t调用方登录 ID:%t%4%n A trusted logon process has registered with the Local Security Authority.This logon process will be trusted to submit logon requests.%n%n%tLogon Process Name:%t%1%n%tCaller User Name:%t%2%n%tCaller Domain:%t%3%n%tCaller Logon ID:%t%4%n
0x204用来列队审核消息的内部资源已经用完,从而导致部分审核数据丢失。%n%t已丢弃的审核消息数量: %t%1 Internal resources allocated for the queuing of audit messages have been exhausted,leading to the loss of some audits.%n%tNumber of audit messages discarded:%t%1
0x205审核日志已经清除%n%t主要用户名: %t%1%n%t主域: %t%2%n%t主登录 ID: %t%3%n%t客户端用户名: %t%4%n%t客户端域: %t%5%n%t客户端登录 ID: %t%6%n%t客户端进程 ID:%t%7%n The audit log was cleared%n%tPrimary User Name:%t%1%n%tPrimary Domain:%t%2%n%tPrimary Logon ID:%t%3%n%tClient User Name:%t%4%n%tClient Domain:%t%5%n%tClient Logon ID:%t%6%n%tClient Process ID:%t%7%n
0x206安全帐户管理器已经加载通知数据包。任何帐户或密码更改信息会通知这个通知数据包。%n通知数据包名: %t%1 An notification package has been loaded by the Security Account Manager.This package will be notified of any account or password changes.%nNotification Package Name:%t%1
0x207无效使用 LPC 端口。%n%t进程 ID: %1%n%t映像文件名: %2%n%t主要用户名:%t%3%n%t主要域:%t%4%n%t主要登录 ID:%t%5%n%t客户端用户名:%t%6%n%t客户端域:%t%7%n%t客户端登录 ID:%t%8%n%t无效使用: %9%n%t服务器端口名:%t%10%n Invalid use of LPC port.%n%tProcess ID: %1%n%tImage File Name: %2%n%tPrimary User Name:%t%3%n%tPrimary Domain:%t%4%n%tPrimary Logon ID:%t%5%n%tClient User Name:%t%6%n%tClient Domain:%t%7%n%tClient Logon ID:%t%8%n%tInvalid use: %9%n%tServer Port Name:%t%10%n
0x208系统时间已更改。%n进程 ID:%t%t%1%n进程名:%t%t%2%n主要用户名:%t%3%n主要域:%t%t%4%n主要登录 ID:%t%t%5%n客户端用户名:%t%t%6%n客户端域:%t%t%7%n客户端登录:%t%t%8%n上一时间:%t%t%10 %9%n新时间:%t%t%12 %11%n The system time was changed.%nProcess ID:%t%t%1%nProcess Name:%t%t%2%nPrimary User Name:%t%3%nPrimary Domain:%t%t%4%nPrimary Logon ID:%t%t%5%nClient User Name:%t%t%6%nClient Domain:%t%t%7%nClient Logon ID:%t%t%8%nPrevious Time:%t%t%10 %9%nNew Time:%t%t%12 %11%n
0x209无法记录事件到安全日志:%n%t状态码:%t%t%1%n%tCrashOnAuditFail 的值:%t%2%n%t失败审核的数量:%t%3%n Unable to log events to security log:%n%tStatus code:%t%t%1%n%tValue of CrashOnAuditFail:%t%2%n%tNumber of failed audits:%t%3%n
0x20B安全日志现在使用了 %1。 The security log is now %1 percent full.
0x20C事件日志自动备份%n%t日志:%t%1%n%t文件:%t%2%n%t状态:%t%3%n Event log auto-backup%n%tLog:%t%1%n%tFile:%t%2%n%tStatus:%t%3%n
0x20D管理员从 CrashOnAuditFail 中恢复系统。LSA 将立即接受非管理员登录。一些可审核的活动可能未记录。%n%tCrashOnAuditFail 的值:%t%1%n Administrator recovered system from CrashOnAuditFail. LSA will now accept non-administrative logons.Some auditable activity might not have been recorded.%n%tValue of CrashOnAuditFail:%t%1%n
0x20E安全数据包已由本地安全授权加载。%n安全数据包名称:%t%1 A security package has been loaded by the Local Security Authority.%nSecurity Package Name:%t%1
0x210登录成功:%n%t用户名: %t%1%n%t域: %t%t%2%n%t登录 ID: %t%t%3%n%t登录类型: %t%4%n%t登录进程: %t%5%n%t身份验证数据包: %t%6%n%t工作站名:%t%7%n%t登录 GUID:%t%8%n%t调用方用户名:%t%9%n%t调用方域:%t%10%n%t调用方登录 ID:%t%11%n%t调用方进程 ID: %12%n%t传递服务: %13%n%t源网络地址:%t%14%n%t源端口:%t%15%n%t调用方进程名称:%t%16%n Successful Logon:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tLogon Type:%t%4%n%tLogon Process:%t%5%n%tAuthentication Package:%t%6%n%tWorkstation Name:%t%7%n%tLogon GUID:%t%8%n%tCaller User Name:%t%9%n%tCaller Domain:%t%10%n%tCaller Logon ID:%t%11%n%tCaller Process ID: %12%n%tTransited Services: %13%n%tSource Network Address:%t%14%n%tSource Port:%t%15%n%tCaller Process Name:%t%16%n
0x211登录失败:%n%t原因:%t%t用户名未知或密码错误%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录进程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名称:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tUnknown user name or bad password%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x212登录失败: %n%t原因: %t%t违反帐户登录时限%n%t用户名: %t%1%n%t域: %t%t%2%n%t登录类型: %t%3%n%t登录过程: %t%4%n%t身份验证数据包: %t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tAccount logon time restriction violation%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x213登录失败:%n%t原因:%t%t帐户当前停用%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tAccount currently disabled%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x214登录失败:%n%t原因:%t%t指定的用户帐户已经过期%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名::%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tThe specified user account has expired%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x215登录失败:%n%t原因:%t%t不允许用户登录这台计算机%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tUser not allowed to logon at this computer%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x216登录失败:%n%t原因:%t没有授予用户在这台机器上%n%t%t请求的登录类型%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%tThe user has not been granted the requested%n%t%tlogon type at this machine%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x217登录失败:%n%t原因:%t%t帐户的密码已经过期%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tThe specified account's password has expired%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x218登录失败:%n%t原因:%t%tNetLogon 组件没有启动%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %t%10%n%t传递服务: %t%11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tThe NetLogon component is not active%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID:%t%10%n%tTransited Services:%t%11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x219登录失败:%n%t原因:%t%t登录时出现错误%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t状态代码:%t%7%n%t子状态代码:%t%8%n%t调用方用户名:%t%9%n%t调用方域:%t%10%n%t调用方登录 ID:%t%11%n%t调用方进程 ID: %t%12%n%t传递服务: %t%13%n%t源网络地址:%t%14%n%t源端口:%t%15%n%t调用方进程名称:%t%16%n Logon Failure:%n%tReason:%t%tAn error occurred during logon%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tStatus code:%t%7%n%tSubstatus code:%t%8%n%tCaller User Name:%t%9%n%tCaller Domain:%t%10%n%tCaller Logon ID:%t%11%n%tCaller Process ID:%t%12%n%tTransited Services:%t%13%n%tSource Network Address:%t%14%n%tSource Port:%t%15%n%tCaller Process Name:%t%16%n
0x21A用户注销:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t登录类型:%t%4%n User Logoff:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tLogon Type:%t%4%n
0x21B登录失败:%n%t原因:%t%t帐户已经锁定%n%t用户名:%t%1%n%t域:%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t身份验证数据包:%t%5%n%t工作站名:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %10%n%t传递服务: %11%n%t源网络地址:%t%12%n%t源端口:%t%13%n%t调用方进程名称:%t%14%n Logon Failure:%n%tReason:%t%tAccount locked out%n%tUser Name:%t%1%n%tDomain:%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID: %10%n%tTransited Services: %11%n%tSource Network Address:%t%12%n%tSource Port:%t%13%n%tCaller Process Name:%t%14%n
0x21C成功的网络登录:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t登录类型:%t%4%n%t登录过程:%t%5%n%t身份验证数据包:%t%6%n%t工作站名:%t%7%n%t登录 GUID:%t%8%n%t调用方用户名:%t%9%n%t调用方域:%t%10%n%t调用方登录 ID:%t%11%n%t调用方进程 ID: %12%n%t传递服务: %13%n%t源网络地址:%t%14%n%t源端口:%t%15%n%t调用方进程名称:%t%16%n Successful Network Logon:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tLogon Type:%t%4%n%tLogon Process:%t%5%n%tAuthentication Package:%t%6%n%tWorkstation Name:%t%7%n%tLogon GUID:%t%8%n%tCaller User Name:%t%9%n%tCaller Domain:%t%10%n%tCaller Logon ID:%t%11%n%tCaller Process ID: %12%n%tTransited Services: %13%n%tSource Network Address:%t%14%n%tSource Port:%t%15%n%tCaller Process Name:%t%16%n
0x21DIKE 安全关联已建立。%n模式: %n%1%n对等机身份: %n%2%n筛选器: %n%3%n参数: %n%4%n IKE security association established.%nMode: %n%1%nPeer Identity: %n%2%nFilter: %n%3%nParameters: %n%4%n
0x21EIKE 安全关联已结束。%n模式: 数据保护(快速模式)筛选器: %n%1%n入站 SPI: %n%2%n出站 SPI: %n%3%n IKE security association ended.%nMode: Data Protection (Quick mode)Filter: %n%1%nInbound SPI: %n%2%nOutbound SPI: %n%3%n
0x21FIKE 安全关联已结束。%n模式: 密钥交换(主要模式)%n筛选器: %n%1%n IKE security association ended.%nMode: Key Exchange (Main mode)%nFilter: %n%1%n
0x220由于对等机无法身份验证,IKE 安全关联未能建立。未能建立证书信息。%n对等机身份: %n%1%n筛选器: %n%2%n IKE security association establishment failed because peer could not authenticate.The certificate trust could not be established.%nPeer Identity: %n%1%nFilter: %n%2%n
0x221IKE 对等机身份验证没有成功。%n对等机身份: %n%1%n筛选器: %n%2%n IKE peer authentication failed.%nPeer Identity: %n%1%nFilter: %n%2%n
0x222由于对等机发送了无效提议,IKE 安全关联建立没有成功。%n模式: %n%1%n筛选器: %n%2%n属性: %n%3%n要求的数值: %n%4%n收到的数值: %n%5%n IKE security association establishment failed because peersent invalid proposal.%nMode: %n%1%nFilter: %n%2%nAttribute: %n%3%nExpected value: %n%4%nReceived value: %n%5%n
0x223IKE 安全关联协商失败。%n模式: %n%1%n筛选器: %n%2%n对等机身份: %n%3%n 失败点: %n%4%n失败原因: %n%5%n额外状态: %n%6%n IKE security association negotiation failed.%nMode: %n%1%nFilter: %n%2%nPeer Identity: %n%3%nFailure Point: %n%4%nFailure Reason: %n%5%nExtra Status: %n%6%n
0x224登录失败:%n%t原因:%t%t域 sid 不一致%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t验证数据包:%t%5%n%t工作站名:%t%6%t传递服务:%t%7%n Logon Failure:%n%tReason:%t%tDomain sid inconsistent%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%tTransited Services:%t%7%n
0x225登录失败:%n%t原因: %t筛选了所有的 sid%n%t用户名:%t%1%n%t域:%t%2%n%t登录类型:%t%3%n%t登录过程:%t%4%n%t验证数据包%t: %5%n%t工作站名:%t%6 Logon Failure:%n%tReason: %tAll sids were filtered out%n%tUser Name:%t%1%n%tDomain:%t%2%n%tLogon Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package%t: %5%n%tWorkstation Name:%t%6
0x226%1%n %1%n
0x227用户要求的注销:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n User initiated logoff:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n
0x228使用明确凭据的登录尝试:%n登录的用户:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t登录 GUID:%t%4%n凭据被使用的用户:%n%t目标用户名:%t%5%n%t目标域:%t%6%n%t目标登录 GUID: %7%n%n目标服务器名称:%t%8%n目标服务器信息:%t%9%n调用方进程 ID:%t%10%n源网络地址:%t%11%n源端口:%t%12%n调用方进程名称:%t%13%n Logon attempt using explicit credentials:%nLogged on user:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tLogon GUID:%t%4%nUser whose credentials were used:%n%tTarget User Name:%t%5%n%tTarget Domain:%t%6%n%tTarget Logon GUID: %7%n%nTarget Server Name:%t%8%nTarget Server Info:%t%9%nCaller Process ID:%t%10%nSource Network Address:%t%11%nSource Port:%t%12%nCaller Process Name:%t%13%n
0x229%t用户名:%t%1%n%t域:%t%%t%2%n%t请求类型:%t%3%n%t登录进程:%t%4%n%t验证数据包:%t%5%n%t工作站名称:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方进程 ID: %10%n%t传递服务: %11%n%t调用方进程名称:%t%12%n %tUser Name:%t%1%n%tDomain:%t%%t%2%n%tRequest Type:%t%3%n%tLogon Process:%t%4%n%tAuthentication Package:%t%5%n%tWorkstation Name:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Process ID: %10%n%tTransited Services: %11%n%tCaller Process Name:%t%12%n
0x22A已建立 IPSec 主模式安全关联。没有配置用户模式。%n键控模块类型: %1%n本地地址: %2%n远程地址: %3%n本地端口: %4%n远程端口: %5%n对等专用地址: %6%n主模式身份验证方法: %7%n主模式自身 Id: %8%n主模式对等 Id: %9%n密码算法: %10%n完整性算法: %11%n生存时间(秒): %12%n主模式模拟: %13%n主模式 SA LUID: %14%n IPSec main mode security association established. User mode is not configured.%nKeying module type: %1%nLocal address: %2%nRemote address: %3%nLocal port: %4%nRemote port: %5%nPeer private address: %6%nMain mode authentication method: %7%nMain mode my Id: %8%nMain mode peer Id: %9%nCipher algorithm: %10%nIntegrity algorithm: %11%nLifetime (seconds): %12%nMain mode impersonation: %13%nMain mode SA LUID: %14%n
0x22B已建立 IPSec 主模式安全关联。没有配置用户模式。%n键控模块类型: %1%n本地地址: %2%n远程地址: %3%n本地端口: %4%n远程端口: %5%n对等专用地址: %6%n主模式身份验证方法: %7%n主模式对等使用者: %n%8%n主模式对等颁发证书颁发机构: %n%9%n主模式对等根证书颁发机构: %n%10%n主模式对等 SHA 指纹: %n%11%n主模式自身使用者: %n%12%n主模式自身 SHA 指纹: %n%13%n密码算法: %14%n完整性算法: %15%n生存时间(秒): %16%n主模式模拟: %17%n主模式 SA LUID: %18%n IPSec main mode security association established. User mode is not configured.%nKeying module type: %1%nLocal address: %2%nRemote address: %3%nLocal port: %4%nRemote port: %5%nPeer private address: %6%nMain mode authentication method: %7%nMain mode peer subject: %n%8%nMain mode peer issuing certificate authority: %n%9%nMain mode peer root certificate authority: %n%10%nMain mode peer SHA thumbprint: %n%11%nMain mode my subject: %n%12%nMain mode my SHA thumbprint: %n%13%nCipher algorithm: %14%nIntegrity algorithm: %15%nLifetime (seconds): %16%nMain mode impersonation: %17%nMain mode SA LUID: %18%n
0x22C建立 IPSec 主模式安全关联失败。%n键控模块类型: %1%n本地地址: %2%n远程地址: %3%n本地端口: %4%n远程端口: %5%n对等专用地址: %6%n主模式身份验证方法: %7%n主模式对等使用者: %n%8%n主模式对等颁发证书颁发机构: %n%9%n主模式对等根证书颁发机构: %n%10%n主模式对等 SHA 指纹: %n%11%n主模式自身使用者: %n%12%n主模式自身 SHA 指纹: %n%13%n失败点: %14%n失败原因: %15%n主模式 IKE 状态: %16%n发起程序或响应程序: %17%n主模式模拟: %18%n IPSec main mode security association establishment failed.%nKeying module type: %1%nLocal address: %2%nRemote address: %3%nLocal port: %4%nRemote port: %5%nPeer private address: %6%nMain mode authentication method: %7%nMain mode peer subject: %n%8%nMain mode peer issuing certificate authority: %n%9%nMain mode peer root certificate authority: %n%10%nMain mode peer SHA thumbprint: %n%11%nMain mode my subject: %n%12%nMain mode my SHA thumbprint: %n%13%nFailure point: %14%nFailure reason: %15%nMain mode IKE state: %16%nInitiator or Responder: %17%nMain mode impersonation: %18%n
0x22D建立 IPSec 主模式安全关联失败。%n键控模块类型: %1%n本地地址: %2%n远程地址: %3%n本地端口: %4%n远程端口: %5%n对等专用地址: %6%n主模式身份验证模式: %7%n主模式自身 ID: %8%n主模式对等 ID: %9%n失败点: %10%n失败原因: %11%n主模式 IKE 状态: %12%n发起程序或响应程序: %13%n主模式模拟: %14%n IPSec main mode security association establishment failed.%nKeying module type: %1%nLocal address: %2%nRemote address: %3%nLocal port: %4%nRemote port: %5%nPeer private address: %6%nMain mode authentication method: %7%nMain mode my Id: %8%nMain mode peer Id: %9%nFailure point: %10%nFailure reason: %11%nMain mode IKE state: %12%nInitiator or Responder: %13%nMain mode impersonation: %14%n
0x22E建立 IPSec 快速模式安全关联失败。%n键控模块类型: %1%n本地地址: %2%n本地地址掩码: %3%n远程地址: %4%n远程地址掩码: %5%n本地端口: %6%n远程端口: %7%n协议: %8%n封装类型: %9%n失败点: %10%n失败原因: %11%n快速模式 IKE 状态: %12%n发起程序或响应程序: %13%n主模式 SA LUID: %14%n IPSec quick mode security association establishment failed.%nKeying module type: %1%nLocal address: %2%nLocal address mask: %3%nRemote address: %4%nRemote address mask: %5%nLocal port: %6%nRemote port: %7%nProtocol: %8%nEncapsulation type: %9%nFailure point: %10%nFailure reason: %11%nQuick mode IKE state: %12%nInitiator or Responder: %13%nMain mode SA LUID: %14%n
0x22FIPSec 主模式安全关联已结束。%n键控模块类型: %1%n本地地址: %2%n远程地址: %3%n本地端口: %4%n远程端口: %5%n对等专用地址: %6%n主模式 SA LUID: %7%n IPSec main mode security association ended.%nKeying module type: %1%nLocal address: %2%nRemote address: %3%nLocal port: %4%nRemote port: %5%nPeer private address: %6%nMain mode SA LUID: %7%n
0x230打开的对象:%n%t对象服务器:%t%1%n%t对象类型:%t%2%n%t对象名称:%t%3%n%t句柄 ID:%t%4%n%t操作 ID:%t%5%n%t进程 ID:%t%6%n%t映像文件名:%t%7%n%t主要用户名:%t%8%n%t主要域:%t%9%n%t主要登录 ID:%t%10%n%t客户端用户名:%t%11%n%t客户端域:%t%12%n%t客户端登录 ID:%t%13%n%t访问次数:%t%14%n%t特权:%t%15%n%t受限 Sid 计数:%t%16%n%t访问掩码:%t%17%n Object Open:%n%tObject Server:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tHandle ID:%t%4%n%tOperation ID:%t%5%n%tProcess ID:%t%6%n%tImage File Name:%t%7%n%tPrimary User Name:%t%8%n%tPrimary Domain:%t%9%n%tPrimary Logon ID:%t%10%n%tClient User Name:%t%11%n%tClient Domain:%t%12%n%tClient Logon ID:%t%13%n%tAccesses:%t%14%n%tPrivileges:%t%15%n%tRestricted Sid Count:%t%16%n%tAccess Mask:%t%17%n
0x232关闭的句柄:%n%t对象服务器:%t%1%n%t句柄 ID:%t%2%n%t进程 ID:%t%3%n%t映像文件名:%t%4%n Handle Closed:%n%tObject Server:%t%1%n%tHandle ID:%t%2%n%tProcess ID:%t%3%n%tImage File Name:%t%4%n
0x233为删除而打开的对象:%n%t对象服务器:%t%1%n%t对象类型:%t%2%n%t对象名:%t%3%n%t句柄 ID:%t%4%n%t操作 ID:%t{%5,%6}%n%t进程 ID:%t%7%n%t主要用户名:%t%8%n%t主域:%t%9%n%t主要登录 ID:%t%10%n%t客户端用户名:%t%11%n%t客户端域:%t%12%n%t客户端登录 ID:%t%13%n%t访问:%t%t%14%n%t特权:%t%t%15%n%t访问掩码:%t%16%n Object Open for Delete:%n%tObject Server:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tHandle ID:%t%4%n%tOperation ID:%t{%5,%6}%n%tProcess ID:%t%7%n%tPrimary User Name:%t%8%n%tPrimary Domain:%t%9%n%tPrimary Logon ID:%t%10%n%tClient User Name:%t%11%n%tClient Domain:%t%12%n%tClient Logon ID:%t%13%n%tAccesses:%t%t%14%n%tPrivileges:%t%t%15%n%tAccess Mask:%t%16%n
0x234删除的对象: %n%t对象服务器: %t%1%n%t句柄 ID: %t%2%n%t进程 ID: %t%3%n%t映像文件名称:%t%4%n Object Deleted:%n%tObject Server:%t%1%n%tHandle ID:%t%2%n%tProcess ID:%t%3%n%tImage File Name:%t%4%n
0x235对象打开:%n%t对象服务器:%t%1%n%t对象类型:%t%2%n%t对象名:%t%3%n%t句柄 ID:%t%4%n%t操作 ID:%t{%5,%6}%n%t进程 ID:%t%7%n%t过程名:%t%8%n%t主要用户名:%t%9%n%t主域:%t%10%n%t主要登录 ID:%t%11%n%t客户端用户名:%t%12%n%t客户端域:%t%13%n%t客户端登录 ID:%t%14%n%t访问:%t%15%n%t特权:%t%16%n%n%t属性:%n%17%n%t访问掩码:%t%18%n Object Open:%n%tObject Server:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tHandle ID:%t%4%n%tOperation ID:%t{%5,%6}%n%tProcess ID:%t%7%n%tProcess Name:%t%8%n%tPrimary User Name:%t%9%n%tPrimary Domain:%t%10%n%tPrimary Logon ID:%t%11%n%tClient User Name:%t%12%n%tClient Domain:%t%13%n%tClient Logon ID:%t%14%n%tAccesses:%t%15%n%tPrivileges:%t%16%n%n%tProperties:%n%17%n%tAccess Mask:%t%18%n
0x236对象操作:%n%t对象服务器%t%1%n%t操作类型:%t%2%n%t对象类型:%t%3%n%t对象名称:%t%4%n%t句柄 ID:%t%5%n%t主用户名:%t%6%n%t主域:%t%7%n%t主登录 ID:%t%8%n%t客户端用户名:%t%9%n%t客户端域:%t%10%n%t客户端登录 ID:%t%11%n%t访问:%t%12%n%t属性::%n%t%13%n%t其他信息:%t%14%n%t其他信息2:%t%15%n%t访问掩码:%t%16%n Object Operation:%n%tObject Server:%t%1%n%tOperation Type:%t%2%n%tObject Type:%t%3%n%tObject Name:%t%4%n%tHandle ID:%t%5%n%tPrimary User Name:%t%6%n%tPrimary Domain:%t%7%n%tPrimary Logon ID:%t%8%n%tClient User Name:%t%9%n%tClient Domain:%t%10%n%tClient Logon ID:%t%11%n%tAccesses:%t%12%n%tProperties:%n%t%13%n%tAdditional Info:%t%14%n%tAdditional Info2:%t%15%n%tAccess Mask:%t%16%n
0x237对象访问尝试:%n%t对象服务器:%t%1%n%t句柄 ID:%t%2%n%t对象类型:%t%3%n%t进程 ID:%t%4%n%t镜像文件名:%t%5%n%t访问:%t%6%n%t访问掩码:%t%7%n%t对象名称:%t%8%n%t主要用户名:%t%9%n%t主要域:%t%10%n%t主要登录 ID:%t%11%n%t客户端用户名:%t%12%n%t客户端域:%t%13%n%t客户端登录 ID:%t%14%n Object Access Attempt:%n%tObject Server:%t%1%n%tHandle ID:%t%2%n%tObject Type:%t%3%n%tProcess ID:%t%4%n%tImage File Name:%t%5%n%tAccesses:%t%6%n%tAccess Mask:%t%7%n%tObject Name:%t%8%n%tPrimary User Name:%t%9%n%tPrimary Domain:%t%10%n%tPrimary Logon ID:%t%11%n%tClient User Name:%t%12%n%tClient Domain:%t%13%n%tClient Logon ID:%t%14%n
0x238硬链接创建尝试:%n%t主要用户名:%t%1%n%t主域:%t%2%n%t主要登录 ID:%t%3%n%t文件名:%t%4%n%t链接名:%t%5%n Hard link creation attempt:%n%tPrimary User Name:%t%1%n%tPrimary Domain:%t%2%n%tPrimary Logon ID:%t%3%n%tFile Name:%t%4%n%tLink Name:%t%5%n
0x239应用程序客户端上下文创建尝试:%n%t应用程序名称:%t%1%n%t应用程序实例 ID:%t%2%n%t客户端名称:%t%3%n%t客户端域:%t%4%n%t客户端上下文 ID:%t%5%n%t状态:%t%6%n Application client context creation attempt:%n%tApplication Name:%t%1%n%tApplication Instance ID:%t%2%n%tClient Name:%t%3%n%tClient Domain:%t%4%n%tClient Context ID:%t%5%n%tStatus:%t%6%n
0x23A应用程序操作尝试:%n%t应用程序名称:%t%1%n%t应用程序实例 ID:%t%2%n%t对象名称:%t%3%n%t范围名称:%t%4%n%t客户端名称:%t%5%n%t客户端域:%t%6%n%t客户端上下文 ID:%t%7%n%t角色:%t%8%n%t组:%t%9%n%t操作名称:%t%10 (%11)%n Application operation attempt:%n%tApplication Name:%t%1%n%tApplication Instance ID:%t%2%n%tObject Name:%t%3%n%tScope Names:%t%4%n%tClient Name:%t%5%n%tClient Domain:%t%6%n%tClient Context ID:%t%7%n%tRole:%t%8%n%tGroups:%t%9%n%tOperation Name:%t%10 (%11)%n
0x23B应用程序客户端上下文删除:%n%t应用程序名称:%t%1%n%t应用程序实例 ID:%t%2%n%t客户端名称:%t%3%n%t客户端域:%t%4%n%t客户端上下文 ID:%t%5%n Application client context deletion:%n%tApplication Name:%t%1%n%tApplication Instance ID:%t%2%n%tClient Name:%t%3%n%tClient Domain:%t%4%n%tClient Context ID:%t%5%n
0x23C应用程序已经初始化%n%t应用程序名称:%t%1%n%t应用程序实例 ID:%t%2%n%t客户端名称:%t%3%n%t客户端域:%t%4%n%t客户端 ID:%t%5%n%t策略存储 URL:%t%6%n Application Initialized%n%tApplication Name:%t%1%n%tApplication Instance ID:%t%2%n%tClient Name:%t%3%n%tClient Domain:%t%4%n%tClient ID:%t%5%n%tPolicy Store URL:%t%6%n
0x23D%n应用程序-特定的安全事件。%n%t事件源:%t%1%n%t事件 ID:%t%2%n%t%t%3%n%t%t%4%n%t%t%5%n%t%t%6%n%t%t%7%n%t%t%8%n%t%t%9%n%t%t%10%n%t%t%11%n%t%t%12%n%t%t%13%n%t%t%14%n%t%t%15%n%t%t%16%n%t%t%17%n%t%t%18%n%t%t%19%n%t%t%20%n%t%t%21%n%t%t%22%n%t%t%23%n%t%t%24%n%t%t%25%n%t%t%26%n%t%t%27%n %nApplication-specific security event.%n%tEvent Source:%t%1%n%tEvent ID:%t%2%n%t%t%3%n%t%t%4%n%t%t%5%n%t%t%6%n%t%t%7%n%t%t%8%n%t%t%9%n%t%t%10%n%t%t%11%n%t%t%12%n%t%t%13%n%t%t%14%n%t%t%15%n%t%t%16%n%t%t%17%n%t%t%18%n%t%t%19%n%t%t%20%n%t%t%21%n%t%t%22%n%t%t%23%n%t%t%24%n%t%t%25%n%t%t%26%n%t%t%27%n
0x23E已更改对象安全:%n%t对象服务器:%t%1%n%t对象类型:%t%2%n%t对象名称:%t%3%n%t句柄 ID:%t%4%n%t进程 ID:%t%5%n%t映像文件名:%t%6%n%n%t主用户名:%t%7%n%t主域:%t%8%n%t主登录 ID:%t%9%n%t客户端用户名:%t%10%n%t客户端域:%t%11%n%t客户端登录 ID:%t%12%n%t原始安全描述符:%t%13%n%t新安全描述符:%t%14%n Security on object changed:%n%tObject Server:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tHandle ID:%t%4%n%tProcess ID:%t%5%n%tImage File Name:%t%6%n%n%tPrimary User Name:%t%7%n%tPrimary Domain:%t%8%n%tPrimary Logon ID:%t%9%n%tClient User Name:%t%10%n%tClient Domain:%t%11%n%tClient Logon ID:%t%12%n%tOriginal Security Descriptor:%t%13%n%tNew Security Descriptor:%t%14%n
0x240指派给新登录的特殊权限:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t特权:%t%4 Special privileges assigned to new logon:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tPrivileges:%t%4
0x241调用的特许服务:%n%t服务器:%t%t%1%n%t服务:%t%t%2%n%t主要用户名:%t%3%n%t主要域:%t%4%n%t主要登录 ID:%t%5%n%t客户端用户名:%t%6%n%t客户端域:%t%7%n%t客户端登录 ID:%t%8%n%t特权:%t%9%n%t进程 ID:%t%10%n%t进程名称:%t%11 Privileged Service Called:%n%tServer:%t%t%1%n%tService:%t%t%2%n%tPrimary User Name:%t%3%n%tPrimary Domain:%t%4%n%tPrimary Logon ID:%t%5%n%tClient User Name:%t%6%n%tClient Domain:%t%7%n%tClient Logon ID:%t%8%n%tPrivileges:%t%9%n%tProcess ID:%t%10%n%tProcess Name:%t%11
0x242特许的对象操作:%n%t对象服务器:%t%1%n%t对象句柄:%t%2%n%t过程 ID:%t%3%n%t主要用户名:%t%4%n%t主要域:%t%5%n%t主要登录 ID:%t%6%n%t客户端用户名:%t%7%n%t客户端域:%t%8%n%t客户端登录 ID:%t%9%n%t特权:%t%10%n%t对象类型:%t%11%n%t对象名称:%t%12%n%t所需访问:%t%13 Privileged object operation:%n%tObject Server:%t%1%n%tObject Handle:%t%2%n%tProcess ID:%t%3%n%tPrimary User Name:%t%4%n%tPrimary Domain:%t%5%n%tPrimary Logon ID:%t%6%n%tClient User Name:%t%7%n%tClient Domain:%t%8%n%tClient Logon ID:%t%9%n%tPrivileges:%t%10%n%tObject Type:%t%11%n%tObject Name:%t%12%n%tDesired Access:%t%13
0x250已经创建新的过程:%n%t新的进程 ID:%t%1%n%t映像文件名:%t%2%n%t创建者进程 ID:%t%3%n%t用户名:%t%4%n%t域:%t%t%5%n%t登录 ID:%t%t%6%n%t令牌提升类型:%t%7%n A new process has been created:%n%tNew Process ID:%t%1%n%tImage File Name:%t%2%n%tCreator Process ID:%t%3%n%tUser Name:%t%4%n%tDomain:%t%t%5%n%tLogon ID:%t%t%6%n%tToken Elevation Type:%t%7%n
0x251已经退出某过程:%n%t进程 ID:%t%1%n%t映像文件名:%t%2%n%t用户名:%t%3%n%t域:%t%t%4%n%t登录 ID:%t%t%5%n%t退出状态:%t%t%6%n A process has exited:%n%tProcess ID:%t%1%n%tImage File Name:%t%2%n%tUser Name:%t%3%n%tDomain:%t%t%4%n%tLogon ID:%t%t%5%n%tExit Status:%t%t%6%n
0x252对象的句柄被重复:%n%t源句柄 ID:%t%1%n%t源进程 ID:%t%2%n%t目标句柄 ID:%t%3%n%t目标进程 ID:%t%4%n A handle to an object has been duplicated:%n%tSource Handle ID:%t%1%n%tSource Process ID:%t%2%n%tTarget Handle ID:%t%3%n%tTarget Process ID:%t%4%n
0x253已经取得对象的间接访问权:%n%t对象类型:%t%1%n%t对象名称:%t%2%n%t进程 ID:%t%3%n%t主要用户名:%t%4%n%t主要域:%t%5%n%t主要登录 ID:%t%6%n%t客户端用户名:%t%7%n%t客户端域:%t%8%n%t客户端登录 ID:%t%9%n%t访问:%t%10%n%t访问掩码:%t%11%n Indirect access to an object has been obtained:%n%tObject Type:%t%1%n%tObject Name:%t%2%n%tProcess ID:%t%3%n%tPrimary User Name:%t%4%n%tPrimary Domain:%t%5%n%tPrimary Logon ID:%t%6%n%tClient User Name:%t%7%n%tClient Domain:%t%8%n%tClient Logon ID:%t%9%n%tAccesses:%t%10%n%tAccess Mask:%t%11%n
0x254数据保护主密钥备份。%n%t密钥标识符:%t%t%1%n%t恢复服务器:%t%t%2%n%t恢复密钥 ID:%t%t%3%n%t失败原因:%t%t%4%n依据:%n%t 用户名:%t%5%n%t 域名:%t%6%n%t 登录 ID:%t%7 Backup of data protection master key.%n%tKey Identifier:%t%t%1%n%tRecovery Server:%t%t%2%n%tRecovery Key ID:%t%t%3%n%tFailure Reason:%t%t%4%nBy:%n%t User Name:%t%5%n%t Domain Name:%t%6%n%t Logon ID:%t%7
0x255数据保护主密钥恢复。%n%t密钥标识符:%t%t%1%n%t恢复原因:%t%t%3%n%t恢复服务器:%t%t%2%n%t恢复密钥 ID:%t%t%4%n%t失败原因:%t%t%5%n依据:%n%t 用户名:%t%6%n%t 域名:%t%7%n%t 登录 ID:%t%8 Recovery of data protection master key.%n%tKey Identifier:%t%t%1%n%tRecovery Reason:%t%t%3%n%tRecovery Server:%t%t%2%n%tRecovery Key ID:%t%t%4%n%tFailure Reason:%t%t%5%nBy:%n%t User Name:%t%6%n%t Domain Name:%t%7%n%t Logon ID:%t%8
0x256可审核的受保护数据的保护。%n%t数据描述:%t%t%2%n%t密钥标识符:%t%t%1%n%t受保护数据标记:%t%3%n%t保护算法:%t%4%n%t失败原因:%t%t%5%n依据:%n%t 用户名:%t%6%n%t 域名:%t%7%n%t 登录 ID:%t%8 Protection of auditable protected data.%n%tData Description:%t%t%2%n%tKey Identifier:%t%t%1%n%tProtected Data Flags:%t%3%n%tProtection Algorithms:%t%4%n%tFailure Reason:%t%t%5%nBy:%n%t User Name:%t%6%n%t Domain Name:%t%7%n%t Logon ID:%t%8
0x257可审核的受保护数据的非保护。%n%t数据描述:%t%t%2%n%t密钥标识符:%t%t%1%n%t受保护数据标记:%t%3%n%t保护算法:%t%4%n%t失败原因:%t%t%5%n依据:%n%t 用户名:%t%6%n%t 域名:%t%7%n%t 登录 ID:%t%8 Unprotection of auditable protected data.%n%tData Description:%t%t%2%n%tKey Identifier:%t%t%1%n%tProtected Data Flags:%t%3%n%tProtection Algorithms:%t%4%n%tFailure Reason:%t%t%5%nBy:%n%t User Name:%t%6%n%t Domain Name:%t%7%n%t Logon ID:%t%8
0x258分派给进程一个主令牌。%n分配进程信息:%n%t进程 ID:%t%1%n%t映像文件名:%t%2%n%t主用户名:%t%3%n%t主域:%t%4%n%t主登录 ID:%t%5%n新进程信息:%n%t进程 ID:%t%6%n%t映像文件名:%t%7%n%t目标用户名:%t%8%n%t目标域:%t%9%n%t目标登录 ID:%t%10%n A process was assigned a primary token.%nAssigning Process Information:%n%tProcess ID:%t%1%n%tImage File Name:%t%2%n%tPrimary User Name:%t%3%n%tPrimary Domain:%t%4%n%tPrimary Logon ID:%t%5%nNew Process Information:%n%tProcess ID:%t%6%n%tImage File Name:%t%7%n%tTarget User Name:%t%8%n%tTarget Domain:%t%9%n%tTarget Logon ID:%t%10%n
0x259尝试安装服务:%n%t服务名称:%t%1%n%t服务文件名称:%t%2%n%t服务类型:%t%3%n%t服务启动类型:%t%4%n%t服务帐户:%t%5%n由:%n%t用户名:%t%6%n%t域:%t%t%7%n%t登录 ID:%t%t%8%n Attempt to install service:%n%tService Name:%t%1%n%tService File Name:%t%2%n%tService Type:%t%3%n%tService Start Type:%t%4%n%tService Account:%t%5%nBy:%n%tUser Name:%t%6%n%tDomain:%t%t%7%n%tLogon ID:%t%t%8%n
0x25A已创建的计划任务:%n%t文件名:%t%1%n%t命令:%t%2%n%t触发器:%t%t%3%n%t时间:%t%t%4 %5%n%t标记:%t%t%6%n%t目标用户:%t%7%n由:%n%t用户:%t%t%8%n%t域:%t%t%9%n%t登录 ID:%t%t%10%n Scheduled Task created:%n%tFile Name:%t%1%n%tCommand:%t%2%n%tTriggers:%t%t%3%n%tTime:%t%t%4 %5%n%tFlags:%t%t%6%n%tTarget User:%t%7%nBy:%n%tUser:%t%t%8%n%tDomain:%t%t%9%n%tLogon ID:%t%t%10%n
0x260指派了用户权利:%n%t用户权限:%t%1%n%t指派给:%t%2%n%t指派者:%n%t 用户名:%t%3%n%t 域:%t%t%4%n%t 登录 ID:%t%5%n User Right Assigned:%n%tUser Right:%t%1%n%tAssigned To:%t%2%n%tAssigned By:%n%t User Name:%t%3%n%t Domain:%t%t%4%n%t Logon ID:%t%5%n
0x261删除了用户权利:%n%t用户权利:%t%1%n%t从下列删除:%t%2%n%t执行删除者:%n%t 用户名:%t%3%n%t 域:%t%t%4%n%t 登录 ID:%t%5%n User Right Removed:%n%tUser Right:%t%1%n%tRemoved From:%t%2%n%tRemoved By:%n%t User Name:%t%3%n%t Domain:%t%t%4%n%t Logon ID:%t%5%n
0x262新的受信域:%n%t域名:%t%1%n%t域 ID:%t%2%n%t创建者:%n%t 用户名:%t%3%n%t 域:%t%t%4%n%t 登录 ID:%t%5%n%t信任类型:%t%6%n%t信任方向:%t%7%n%t信任属性:%t%8%n%tSID 筛选:%t%9%n New Trusted Domain:%n%tDomain Name:%t%1%n%tDomain ID:%t%2%n%tEstablished By:%n%t User Name:%t%3%n%t Domain:%t%t%4%n%t Logon ID:%t%5%n%tTrust Type:%t%6%n%tTrust Direction:%t%7%n%tTrust Attributes:%t%8%n%tSID Filtering:%t%9%n
0x263已删除受信域:%n%t域名:%t%1%n%t域 ID:%t%2%n%t删除者:%n%t 用户名:%t%3%n%t 域:%t%t%4%n%t 登录 ID:%t%5%n Trusted Domain Removed:%n%tDomain Name:%t%1%n%tDomain ID:%t%2%n%tRemoved By:%n%t User Name:%t%3%n%t Domain:%t%t%4%n%t Logon ID:%t%5%n
0x264审核策略更改:%n新策略:%n%t成功%t失败%n%t %3%t %4%t登录/注销%n%t %5%t %6%t对象访问%n%t %7%t %8%t特权使用%n%t %13%t %14%t帐户管理%n%t %11%t %12%t策略更改%n%t %1%t %2%t系统%n%t %9%t %10%t详细跟踪%n%t %15%t %16%t目录服务访问%n%t %17%t %18%t帐户登录%n%n更改人:%n%t 用户名:%t%19%n%t 域名:%t%20%n%t 登录 ID:%t%21 Audit Policy Change:%nNew Policy:%n%tSuccess%tFailure%n%t %3%t %4%tLogon/Logoff%n%t %5%t %6%tObject Access%n%t %7%t %8%tPrivilege Use%n%t %13%t %14%tAccount Management%n%t %11%t %12%tPolicy Change%n%t %1%t %2%tSystem%n%t %9%t %10%tDetailed Tracking%n%t %15%t %16%tDirectory Service Access%n%t %17%t %18%tAccount Logon%n%nChanged By:%n%t User Name:%t%19%n%t Domain Name:%t%20%n%t Logon ID:%t%21
0x265IPSec 服务已经开始: %t%1%n策略来源: %t%2%n%3%n IPSec Services started: %t%1%nPolicy Source: %t%2%n%3%n
0x266IPSec 服务已经被停用: %t%1%n%2%n IPSec Services disabled: %t%1%n%2%n
0x267%1 %1
0x268IPSec 服务遇到一个有可能很严重的故障。%n%1%n IPSec Services encountered a potentially serious failure.%n%1%n
0x269Kerberos 策略已更改:%n更改人:%n%t 用户名:%t%1%n%t 域名:%t%2%n%t 登录 ID:%t%3%n所作的改动:%n('--' 表示没有改动,否则,每个改动显示为:%n: ())%n%4%n Kerberos Policy Changed:%nChanged By:%n%t User Name:%t%1%n%t Domain Name:%t%2%n%t Logon ID:%t%3%nChanges made:%n('--' means no changes, otherwise each change is shown as:%n: ())%n%4%n
0x26A经过加密的数据恢复策略已更改:%n更改人:%n%t 用户名:%t%1%n%t 域名:%t%2%n%t Logon ID:%t%3%n所作的改动:%n('--' 表示没有改动,否则,每个改动显示为:%n: ())%n%4%n Encrypted Data Recovery Policy Changed:%nChanged By:%n%t User Name:%t%1%n%t Domain Name:%t%2%n%t Logon ID:%t%3%nChanges made:%n('--' means no changes, otherwise each change is shown as:%n: ())%n%4%n
0x26B已更改审核安全对象:%n%t主用户名:%t%1%n%t主域:%t%2%n%t主登录 ID:%t%3%n%t客户端用户名:%t%4%n%t客户端域:%t%5%n%t客户端登录 ID:%t%6%n%t原始安全描述符:%t%7%n%t新安全描述符:%t%8%n Audit Security Object changed:%n%tPrimary User Name:%t%1%n%tPrimary Domain:%t%2%n%tPrimary Logon ID:%t%3%n%tClient User Name:%t%4%n%tClient Domain:%t%5%n%tClient Logon ID:%t%6%n%tOriginal Security Descriptor:%t%7%n%tNew Security Descriptor:%t%8%n
0x26C受信域信息已被修改:%n%t域名:%t%1%n%t域 ID:%t%2%n%t修改人:%n%t 用户名:%t%3%n%t 域:%t%t%4%n%t 登录 ID:%t%5%n%t信任类型:%t%6%n%t信任方向:%t%7%n%t信任属性:%t%8%n%tSID 筛选:%t%9%n Trusted Domain Information Modified:%n%tDomain Name:%t%1%n%tDomain ID:%t%2%n%tModified By:%n%t User Name:%t%3%n%t Domain:%t%t%4%n%t Logon ID:%t%5%n%tTrust Type:%t%6%n%tTrust Direction:%t%7%n%tTrust Attributes:%t%8%n%tSID Filtering:%t%9%n
0x26D授予了系统安全访问:%n%t授予了访问:%t%4%n%t修改了帐户:%t%5%n%t分配者:%n%t 用户名:%t%1%n%t 域:%t%t%2%n%t 登录 ID:%t%3%n System Security Access Granted:%n%tAccess Granted:%t%4%n%tAccount Modified:%t%5%n%tAssigned By:%n%t User Name:%t%1%n%t Domain:%t%t%2%n%t Logon ID:%t%3%n
0x26E删除了系统安全访问:%n%t删除了访问:%t%4%n%t修改了帐户:%t%5%n%t删除者:%n%t 用户名:%t%1%n%t 域:%t%t%2%n%t 登录 ID:%t%3%n System Security Access Removed:%n%tAccess Removed:%t%4%n%tAccount Modified:%t%5%n%tRemoved By:%n%t User Name:%t%1%n%t Domain:%t%t%2%n%t Logon ID:%t%3%n
0x26F系统审核策略更改:%n 类别:%t%1%n 子类别:%t%2%n 子类别 GUID:%t%3%n 更改:%t%4%n%n更改者:%n 用户名:%t%5%n 域名:%t%6%n 登录 ID:%t%7 System Audit Policy Change:%n Category:%t%1%n Sub Category:%t%2%n Sub Category Guid:%t%3%n Changes:%t%4%n%nChanged By:%n User Name:%t%5%n Domain Name:%t%6%n Logon ID:%t%7
0x270创建了用户帐户:%n%t新的帐户名:%t%1%n%t新域:%t%2%n%t新帐户标识:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%t显示名称:%t%9%n%t用户主要名称:%t%10%n%t主目录:%t%11%n%t主驱动器:%t%12%n%t脚本路径:%t%13%n%t配置文件路径:%t%14%n%t用户工作站:%t%15%n%t上一次设置的密码:%t%16%n%t帐户过期:%t%17%n%t主要组 ID:%t%18%n%tAllowedToDelegateTo:%t%19%n%t旧 UAC 值:%t%20%n%t新 UAC 值:%t%21%n%t用户帐户控制:%t%22%n%t用户参数:%t%23%n%tSid 历史:%t%24%n%t登录时间:%t%25%n User Account Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges%t%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tDisplay Name:%t%9%n%tUser Principal Name:%t%10%n%tHome Directory:%t%11%n%tHome Drive:%t%12%n%tScript Path:%t%13%n%tProfile Path:%t%14%n%tUser Workstations:%t%15%n%tPassword Last Set:%t%16%n%tAccount Expires:%t%17%n%tPrimary Group ID:%t%18%n%tAllowedToDelegateTo:%t%19%n%tOld UAC Value:%t%20%n%tNew UAC Value:%t%21%n%tUser Account Control:%t%22%n%tUser Parameters:%t%23%n%tSid History:%t%24%n%tLogon Hours:%t%25%n
0x272启用了用户帐户:%n%t目标帐户名:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n User Account Enabled:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n
0x273更改密码尝试:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Change Password Attempt:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x274设置了用户帐户密码:%n%t目标帐户名:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n User Account password set:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n
0x275停用了用户帐户:%n%t目标帐户名:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n User Account Disabled:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n
0x276删除了用户帐户:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n User Account Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x277创建了启用安全的全局组:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Global Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x278添加了启用安全的全局组成员:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Global Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x279删除了启用安全的全局组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Global Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x27A删除了启用安全的全局组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Enabled Global Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x27B创建了启用安全的本地组:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Local Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x27C添加了启用安全的本地组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Local Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x27D删除了启用安全的本地组:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Local Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x27E删除了启用安全的本地组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Enabled Local Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x27F更改了启用安全的本地组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Local Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x280一般帐户数据库更改:%n%t更改类型:%t%1%n%t对象类型:%t%2%n%t对象名称:%t%3%n%t对象 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方所属域:%t%6%n%t调用方登录 ID:%t%7%n General Account Database Change:%n%tType of change:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tObject ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n
0x281更改了启用安全的全局组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Global Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x282更改了用户帐户:%n%t目标帐户名称:%t%2%n%t目标域:%t%3%n%t目标帐户 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方所属域:%t%6%n%t调用方登录 ID:%t%7%n%t特权:%t%8%n更改的属性:%n%tSAM 帐户名称:%t%9%n%t显示名称:%t%10%n%t用户主要名称:%t%11%n%t主目录:%t%12%n%t主驱动器:%t%13%n%t脚本路径:%t%14%n%t配置文件路径:%t%15%n%t用户工作站:%t%16%n%t上一次设置的密码:%t%17%n%t帐户过期:%t%18%n%t主要组 ID:%t%19%n%tAllowedToDelegateTo:%t%20%n%t旧 UAC 值:%t%21%n%t新 UAC 值:%t%22%n%t用户帐户控制:%t%23%n%t用户参数:%t%24%n%tSid 历史:%t%25%n%t登录时间(以小时计):%t%26%n User Account Changed:%n%tTarget Account Name:%t%2%n%tTarget Domain:%t%3%n%tTarget Account ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n%tPrivileges:%t%8%nChanged Attributes:%n%tSam Account Name:%t%9%n%tDisplay Name:%t%10%n%tUser Principal Name:%t%11%n%tHome Directory:%t%12%n%tHome Drive:%t%13%n%tScript Path:%t%14%n%tProfile Path:%t%15%n%tUser Workstations:%t%16%n%tPassword Last Set:%t%17%n%tAccount Expires:%t%18%n%tPrimary Group ID:%t%19%n%tAllowedToDelegateTo:%t%20%n%tOld UAC Value:%t%21%n%tNew UAC Value:%t%22%n%tUser Account Control:%t%23%n%tUser Parameters:%t%24%n%tSid History:%t%25%n%tLogon Hours:%t%26%n
0x283更改了域策略:%1 modified%n%t域名:%t%t%2%n%t域 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方所属域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%t最小密码存留期:%t%8%n%t最大密码存留期:%t%9%n%t强制注销:%t%10%n%t锁定阈值:%t%11%n%t锁定观察窗口:%t%12%n%t锁定持续时间:%t%13%n%t密码属性:%t%14%n%t最小密码长度:%t%15%n%t密码历史长度:%t%16%n%t计算机帐户配额 :%t%17%n %t混合域模式:%t%18%n%t域行为版本:%t%19%n%tOEM 信息:%t%20%n Domain Policy Changed: %1 modified%n%tDomain Name:%t%t%2%n%tDomain ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tMin. Password Age:%t%8%n%tMax. Password Age:%t%9%n%tForce Logoff:%t%10%n%tLockout Threshold:%t%11%n%tLockout Observation Window:%t%12%n%tLockout Duration:%t%13%n%tPassword Properties:%t%14%n%tMin. Password Length:%t%15%n%tPassword History Length:%t%16%n%tMachine Account Quota:%t%17%n%tMixed Domain Mode:%t%18%n%tDomain Behavior Version:%t%19%n%tOEM Information:%t%20%n
0x284用户帐户被锁住:%n%t目标帐户名:%t%1%n%t目标帐户 ID:%t%3%n%t调用方机器名:%t%2%n%t调用方用户名:%t%4%n%t调用方所属域:%t%5%n%t调用方登录 ID:%t%6%n User Account Locked Out:%n%tTarget Account Name:%t%1%n%tTarget Account ID:%t%3%n%tCaller Machine Name:%t%2%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n
0x285创建了计算机帐户:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%t显示名称:%t%9%n%t用户主要名称:%t%10%n%t主目录:%t%11%n%t主驱动器:%t%12%n%t脚本路径:%t%13%n%t配置文件路径:%t%14%n%t用户工作站:%t%15%n%t上一次设置的密码:%t%16%n%t帐户过期:%t%17%n%t主要组 ID:%t%18%n%tAllowedToDelegateTo:%t%19%n%t旧 UAC 值:%t%20%n%t新 UAC 值:%t%21%n%t用户帐户控制:%t%22%n%t用户参数:%t%23%n%tSid 历史:%t%24%n%t登录时间(以小时计):%t%25%n%tDNS 主机名称:%t%26%n%t服务主要名称:%t%27%n Computer Account Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges%t%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tDisplay Name:%t%9%n%tUser Principal Name:%t%10%n%tHome Directory:%t%11%n%tHome Drive:%t%12%n%tScript Path:%t%13%n%tProfile Path:%t%14%n%tUser Workstations:%t%15%n%tPassword Last Set:%t%16%n%tAccount Expires:%t%17%n%tPrimary Group ID:%t%18%n%tAllowedToDelegateTo:%t%19%n%tOld UAC Value:%t%20%n%tNew UAC Value:%t%21%n%tUser Account Control:%t%22%n%tUser Parameters:%t%23%n%tSid History:%t%24%n%tLogon Hours:%t%25%n%tDNS Host Name:%t%26%n%tService Principal Names:%t%27%n
0x286更改了计算机帐户:%n%t%1%n%t目标帐户名称:%t%2%n%t目标域:%t%3%n%t目标帐户 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方域:%t%6%n%t调用方登录 ID:%t%7%n%t特权:%t%8%n更改的属性:%n%tSAM 帐户名称:%t%9%n%t显示名称:%t%10%n%t用户主要名称:%t%11%n%t主目录:%t%12%n%t主驱动器:%t%13%n%t脚本路径:%t%14%n%t配置文件路径:%t%15%n%t用户工作站:%t%16%n%t上一次设置的密码:%t%17%n%t帐户过期:%t%18%n%t主要组 ID:%t%19%n%tAllowedToDelegateTo:%t%20%n%t旧 UAC 值:%t%21%n%t新 UAC 值:%t%22%n%t用户帐户控制:%t%23%n%t用户参数:%t%24%n%tSid 历史:%t%25%n%t登录时间(以小时计):%t%26%n%tDNS 主机名称:%t%27%n%t服务主要名称:%t%28%n Computer Account Changed:%n%t%1%n%tTarget Account Name:%t%2%n%tTarget Domain:%t%3%n%tTarget Account ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n%tPrivileges:%t%8%nChanged Attributes:%n%tSam Account Name:%t%9%n%tDisplay Name:%t%10%n%tUser Principal Name:%t%11%n%tHome Directory:%t%12%n%tHome Drive:%t%13%n%tScript Path:%t%14%n%tProfile Path:%t%15%n%tUser Workstations:%t%16%n%tPassword Last Set:%t%17%n%tAccount Expires:%t%18%n%tPrimary Group ID:%t%19%n%tAllowedToDelegateTo:%t%20%n%tOld UAC Value:%t%21%n%tNew UAC Value:%t%22%n%tUser Account Control:%t%23%n%tUser Parameters:%t%24%n%tSid History:%t%25%n%tLogon Hours:%t%26%n%tDNS Host Name:%t%27%n%tService Principal Names:%t%28%n
0x287删除了计算机帐户:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Computer Account Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x288创建了禁用安全的本地组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Local Group Created:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x289更改了禁用安全的本地组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Local Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x28A添加了禁用安全的本地组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Local Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x28B删除了禁用安全的本地组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Local Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x28C删除了禁用安全的本地组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Disabled Local Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x28D创建了禁用安全的全局组:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Global Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x28E更改了禁用安全的全局组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Global Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x28F添加了禁用安全的全局组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Global Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x290删除了禁用安全的全局组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Global Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x291删除了禁用安全的全局组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Disabled Global Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x292创建了启用安全的通用组:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Universal Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x293更改了启用安全的通用组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Enabled Universal Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x294添加了启用安全的通用组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Universal Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x295删除了启用安全的通用组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Enabled Universal Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x296删除了启用安全的通用组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Enabled Universal Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x297创建了禁用安全的通用组:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Universal Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x298更改了禁用安全的通用组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Security Disabled Universal Group Changed:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x299添加了禁用安全的通用组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Universal Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x29A删除了禁用安全的通用组成员:%n%t成员名称:%t%1%n%t成员ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Security Disabled Universal Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x29B删除了禁用安全的通用组:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Security Disabled Universal Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x29C更改了组类型:%n%t%1%n%t目标帐户名称:%t%2%n%t目标域:%t%3%n%t目标帐户 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方域:%t%6%n%t调用方登录 ID:%t%7%n%t特权:%t%8%n Group Type Changed:%n%t%1%n%tTarget Account Name:%t%2%n%tTarget Domain:%t%3%n%tTarget Account ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n%tPrivileges:%t%8%n
0x29D添加 SID 历史:%n%t源帐户名称:%t%1%n%t源帐户 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n%tSidList:%t%10%n Add SID History:%n%tSource Account Name:%t%1%n%tSource Account ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n%tSidList:%t%10%n
0x29E添加 SID 历史:%n%t源帐户名:%t%1%n%t目标帐户名:%t%2%n%t目标域:%t%3%n%t目标帐户 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方域:%t%6%n%t调用方登录 ID:%t%7%n%t特权:%t%8%n Add SID History:%n%tSource Account Name:%t%1%n%tTarget Account Name:%t%2%n%tTarget Domain:%t%3%n%tTarget Account ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n%tPrivileges:%t%8%n
0x29F未锁定帐户:%n%t目标帐户名:%t%1%n%t目标域:%t%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n User Account Unlocked:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n
0x2A0验证票证请求:%n%t用户名:%t%t%1%n%t提供的领域名:%t%2%n%t用户 ID:%t%t%t%3%n%t服务名:%t%t%4%n%t服务 ID:%t%t%5%n%t票证选项:%t%t%6%n%t结果码:%t%t%7%n%t票证加密类型:%t%8%n%t预身份验证类型:%t%9%n%t客户端地址:%t%t%10%n%t证书颁发机构名称:%t%11%n%t证书序列号:%t%12%n%t证书指纹:%t%13%n Authentication Ticket Request:%n%tUser Name:%t%t%1%n%tSupplied Realm Name:%t%2%n%tUser ID:%t%t%t%3%n%tService Name:%t%t%4%n%tService ID:%t%t%5%n%tTicket Options:%t%t%6%n%tResult Code:%t%t%7%n%tTicket Encryption Type:%t%8%n%tPre-Authentication Type:%t%9%n%tClient Address:%t%t%10%n%tCertificate Issuer Name:%t%11%n%tCertificate Serial Number:%t%12%n%tCertificate Thumbprint:%t%13%n
0x2A1服务票证请求:%n%t用户名:%t%t%1%n%t用户域:%t%t%2%n%t服务名:%t%t%3%n%t服务 ID:%t%t%4%n%t票证选项:%t%t%5%n%t票证加密类型:%t%6%n%t客户端地址:%t%t%7%n%t失败代码:%t%t%8%n%t登录 GUID:%t%t%9%n%t传递服务:%t%10%n Service Ticket Request:%n%tUser Name:%t%t%1%n%tUser Domain:%t%t%2%n%tService Name:%t%t%3%n%tService ID:%t%t%4%n%tTicket Options:%t%t%5%n%tTicket Encryption Type:%t%6%n%tClient Address:%t%t%7%n%tFailure Code:%t%t%8%n%tLogon GUID:%t%t%9%n%tTransited Services:%t%10%n
0x2A2续订服务票证:%n %t用户名:%t%1%n %t用户域:%t%2%n %t服务名:%t%3%n %t服务 ID:%t%4%n %t票证选项:%t%5%n%t票证加密类型:%t%6%n%t客户端地址:%t%7%n Service Ticket Renewed:%n%tUser Name:%t%1%n%tUser Domain:%t%2%n%tService Name:%t%3%n%tService ID:%t%4%n%tTicket Options:%t%5%n%tTicket Encryption Type:%t%6%n%tClient Address:%t%7%n
0x2A3预验证失败:%n%t用户名:%t%1%n%t用户 ID:%t%t%2%n%t服务名:%t%3%n%t预验证类型:%t%4%n%t失败代码:%t%5%n%t客户端地址:%t%6%n%t证书颁发者名称:%t%7%n%t证书序列号:%t%8%n%t证书指纹:%t%9%n Pre-authentication failed:%n%tUser Name:%t%1%n%tUser ID:%t%t%2%n%tService Name:%t%3%n%tPre-Authentication Type:%t%4%n%tFailure Code:%t%5%n%tClient Address:%t%6%n%tCertificate Issuer Name:%t%7%n%tCertificate Serial Number:%t%8%n%tCertificate Thumbprint:%t%9%n
0x2A4身份验证票证请求失败:%n%t用户名:%t%1%n%t供应的领域名:%t%2%n%t服务名:%t%3%n%t票证选项:%t%4%n%t失败代码:%t%5%n%t客户地址:%t%6%n Authentication Ticket Request Failed:%n%tUser Name:%t%1%n%tSupplied Realm Name:%t%2%n%tService Name:%t%3%n%tTicket Options:%t%4%n%tFailure Code:%t%5%n%tClient Address:%t%6%n
0x2A5验证票证请求失败:%n %t用户名:%t%1%n %t用户域:%t%2%n %t服务名:%t%3%n %t票证选项:%t%4%n%t失败码:%t%5%n%t客户端地址:%t%6%n Service Ticket Request Failed:%n%tUser Name:%t%1%n%tUser Domain:%t%2%n%tService Name:%t%3%n%tTicket Options:%t%4%n%tFailure Code:%t%5%n%tClient Address:%t%6%n
0x2A6为登录映射的帐户。%n映射帐户:%n %t%1%n客户端名:%n%t%2%n%t映射的名称:%n%t%3%n Account Mapped for Logon.%nMapping Attempted By:%n%t%1%nClient Name:%n%t%2%n%tMapped Name:%n%t%3%n
0x2A7名称:%n%t%2%n无法映射,登录用户为:%t%1%n The name:%n%t%2%ncould not be mapped for logon by:%t%1%n
0x2A8尝试登录的用户: %t%1%n登录帐户: %t%2%n源工作站: %t%3%n错误代码: %t%4%n Logon attempt by:%t%1%nLogon account:%t%2%nSource Workstation:%t%3%nError Code:%t%4%n
0x2A9登录到帐户: %2%n登录的用户: %1%n从工作站: %3%n未成功。错误代码是: %4%n The logon to account: %2%nby: %1%nfrom workstation: %3%nfailed. The error code was: %4%n
0x2AA会话被重新连接到 winstation:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话名称:%t%4%n%t客户端名:%t%5%n%t客户端地址:%t%6 Session reconnected to winstation:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession Name:%t%4%n%tClient Name:%t%5%n%tClient Address:%t%6
0x2AB会话从 winstation 中断连接:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话名称:%t%4%n%t客户端名:%t%5%n%t客户端地址:%t%6 Session disconnected from winstation:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession Name:%t%4%n%tClient Name:%t%5%n%tClient Address:%t%6
0x2AC设置管理员组中成员的 ACL :%n%t目标帐户名:%t%1%n%t目标域:%t%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Set ACLs of members in administrators groups:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x2AD已更改帐户名:%n %t旧帐户名:%t%1%n%t新帐户名:%t%2%n%t目标域:%t%t%3%n%t目标帐户 ID:%t%4%n%t调用方用户名:%t%5%n%t调用方域:%t%6%n%t调用方登录 ID:%t%7%n%t特权:%t%8%n Account Name Changed:%n%tOld Account Name:%t%1%n%tNew Account Name:%t%2%n%tTarget Domain:%t%t%3%n%tTarget Account ID:%t%4%n%tCaller User Name:%t%5%n%tCaller Domain:%t%6%n%tCaller Logon ID:%t%7%n%tPrivileges:%t%8%n
0x2AE下列用户访问的密码:%n%t目标用户名:%t%1%n%t目标用户域:%t%t%2%n由用户:%n%t调用方用户名:%t%3%n%t调用方域:%t%t%4%n%t调用方登录 ID:%t%t%5%n Password of the following user accessed:%n%tTarget User Name:%t%1%n%tTarget User Domain:%t%t%2%nBy user:%n%tCaller User Name:%t%3%n%tCaller Domain:%t%t%4%n%tCaller Logon ID:%t%t%5%n
0x2AF基本应用程序组已经创建:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Basic Application Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x2B0基本应用程序组已经更改:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n Basic Application Group Changed:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x2B1基本应用程序组成员已经添加:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Basic Application Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2B2基本应用程序组成员已经删除:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Basic Application Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2B3基本应用程序组非成员已经添加:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Basic Application Group Non-Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2B4基本应用程序组非成员已经删除:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用方用户名:%t%6%n%t调用方域:%t%7%n%t调用方登录 ID:%t%8%n%t特权:%t%9%n Basic Application Group Non-Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2B5基本应用程序组已经删除:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n Basic Application Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x2B6LDAP 查询组已经创建:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n LDAP Query Group Created:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nAttributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x2B7LDAP 查询组已经更改:%n%t新帐户名称:%t%1%n%t新域:%t%2%n%t新帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n更改的属性:%n%tSAM 帐户名称:%t%8%n%tSID 历史:%t%9%n LDAP Query Group Changed:%n%tNew Account Name:%t%1%n%tNew Domain:%t%2%n%tNew Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%nChanged Attributes:%n%tSam Account Name:%t%8%n%tSid History:%t%9%n
0x2B8LDAP 查询组已经删除:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用域用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n LDAP Query Group Deleted:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n
0x2B9调用了密码策略检查 API:%n%t调用方用户名:%t%1%n%t调用方域:%t%2%n%t调用方登录 ID:%t%3%n%t调用方工作站:%t%4%n%t提供的用户名 (未经过身份验证):%t%5%n%t状态代码:%t%6%n Password Policy Checking API is called:%n%tCaller Username:%t%1%n%tCaller Domain:%t%2%n%tCaller Logon ID:%t%3%n%tCaller Workstation:%t%4%n%tProvided User Name (unauthenticated):%t%5%n%tStatus Code:%t%6%n
0x2BA已经尝试设置目录服务还原模式管理员密码。%n%t调用方用户名:%t%1%n%t调用方域:%t%2%n%t调用方登录 ID:%t%3%n%t调用方工作站:%t%4%n%t状态码:%t%5%n An attempt to set the Directory Services Restore Modeadministrator password has been made.%n%tCaller Username:%t%1%n%tCaller Domain:%t%2%n%tCaller Logon ID:%t%3%n%tCaller Workstation:%t%4%n%tStatus Code:%t%5%n
0x2BB已添加 RODC 特定的本地组成员:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用者用户名:%t%6%n%t调用者域:%t%7%n%t调用者登录 ID:%t%8%n%t权限:%t%9%n RODC SpecifiC Local Group Member Added:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2BC已删除 RODC 特定的本地组成员:%n%t成员名称:%t%1%n%t成员 ID:%t%2%n%t目标帐户名称:%t%3%n%t目标域:%t%4%n%t目标帐户 ID:%t%5%n%t调用者用户名:%t%6%n%t调用者域:%t%7%n%t调用者登录 ID:%t%8%n%t权限:%t%9%n RODC Specific Local Group Member Removed:%n%tMember Name:%t%1%n%tMember ID:%t%2%n%tTarget Account Name:%t%3%n%tTarget Domain:%t%4%n%tTarget Account ID:%t%5%n%tCaller User Name:%t%6%n%tCaller Domain:%t%7%n%tCaller Logon ID:%t%8%n%tPrivileges:%t%9%n
0x2BD已尝试查询帐户是否存在空白密码:%n%t调用方用户名:%t%1%n%t调用方域:%t%2%n%t调用方登录 ID:%t%3%n%t调用方工作站:%t%4%n%t目标帐户名:%t%5%n%t目标帐户域:%t%6%n An attempt was made to query the existence of a blank password for an account:%n%tCaller Username:%t%1%n%tCaller Domain:%t%2%n%tCaller Logon ID:%t%3%n%tCaller Workstation:%t%4%n%tTarget Account Name:%t%5%n%tTarget Account Domain:%t%6%n
0x2C0已锁定工作站:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话 ID:%t%4%n Workstation is locked:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession ID:%t%4%n
0x2C1解锁工作站:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话 ID:%t%4%n Workstation is unlocked:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession ID:%t%4%n
0x2C2调用屏幕保护程序:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话 ID:%t%4%n Screen saver is invoked:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession ID:%t%4%n
0x2C3解除屏幕保护程序:%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%t%3%n%t会话 ID:%t%4%n Screen saver is dismissed:%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%t%3%n%tSession ID:%t%4%n
0x2D0RPC 在解密传入的消息时检测到完整性被破坏。%n%t对等名称:%t%1%n%t协议序列:%t%2%n%t安全性错误:%t%3%n RPC detected an integrity violation while decrypting an incoming message.%n%tPeer Name:%t%1%n%tProtocol Sequence:%t%2%n%tSecurity Error:%t%3%n
0x2D4Kerberos 票证授予票证(TGT)已被拒绝,因为该设备不符合访问控制限制。%n%n帐户信息:%n%t帐户名称:%t%t%1%n%t提供的领域名称:%t%2%n%t用户 ID:%t%t%t%3%n%n身份验证策略信息:%n%t接收器名称:%t%t%16%n%t策略名称:%t%t%17%n%tTGT 生存时间:%t%t%18%n%n设备信息:%n%t设备名称:%t%t%4%n%n服务信息:%n%t服务名称:%t%t%5%n%t服务 ID:%t%t%6%n%n网络信息:%n%t客户端地址:%t%t%11%n%t客户端端口:%t%t%12%n%n其他信息:%n%t票证选项:%t%t%7%n%t结果代码:%t%t%8%n%t票证加密类型:%t%9%n%t预身份验证类型:%t%10%n%n证书信息:%n%t证书颁发者名称:%t%t%13%n%t证书序列号:%t%14%n%t证书指纹:%t%t%15%n%n仅当证书已用于预身份验证时才会提供证书信息。%n%n预身份验证类型、票证选项、加密类型和结果代码是在 RFC 4120 中定义的。 A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.%n%nAccount Information:%n%tAccount Name:%t%t%1%n%tSupplied Realm Name:%t%2%n%tUser ID:%t%t%t%3%n%nAuthentication Policy Information:%n%tSilo Name:%t%t%16%n%tPolicy Name:%t%t%17%n%tTGT Lifetime:%t%t%18%n%nDevice Information:%n%tDevice Name:%t%t%4%n%nService Information:%n%tService Name:%t%t%5%n%tService ID:%t%t%6%n%nNetwork Information:%n%tClient Address:%t%t%11%n%tClient Port:%t%t%12%n%nAdditional Information:%n%tTicket Options:%t%t%7%n%tResult Code:%t%t%8%n%tTicket Encryption Type:%t%9%n%tPre-Authentication Type:%t%10%n%nCertificate Information:%n%tCertificate Issuer Name:%t%t%13%n%tCertificate Serial Number:%t%14%n%tCertificate Thumbprint:%t%t%15%n%nCertificate information is only provided if a certificate was used for pre-authentication.%n%nPre-authentication types, ticket options, encryption types and result codes are defined in RFC 4120.
0x2D5Kerberos 服务票证已被拒绝,因为用户和/或设备不符合访问控制限制。%n%n帐户信息:%n%t帐户名称:%t%t%1%n%t帐户域:%t%t%2%n%t登录 GUID:%t%t%11%n%n身份验证策略信息:%n%t接收器名称:%t%t%13%n%t策略名称:%t%t%14%n%n设备信息:%n%t设备名称:%t%t%3%n%n服务信息:%n%t服务名称:%t%t%4%n%t服务 ID:%t%t%5%n%n网络信息:%n%t客户端地址:%t%t%8%n%t客户端端口:%t%t%9%n%n其他信息:%n%t票证选项:%t%t%6%n%t票证加密类型:%t%7%n%t故障代码:%t%t%10%n%t传递服务:%t%12%n%n每次请求访问资源(例如计算机或 Windows 服务)时生成此事件。服务名称指示已请求访问的资源。%n%n此事件可以与 Windows 登录事件关联,方法是比较每个事件中的登录 GUID 字段。登录事件发生在所访问的计算机上,该计算机通常不是颁发服务票证的域控制器所在的计算机。%n%n票证选项、加密类型和故障代码是在 RFC 4120 中定义的。 A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions.%n%nAccount Information:%n%tAccount Name:%t%t%1%n%tAccount Domain:%t%t%2%n%tLogon GUID:%t%t%11%n%nAuthentication Policy Information:%n%tSilo Name:%t%t%13%n%tPolicy Name:%t%t%14%n%nDevice Information:%n%tDevice Name:%t%t%3%n%nService Information:%n%tService Name:%t%t%4%n%tService ID:%t%t%5%n%nNetwork Information:%n%tClient Address:%t%t%8%n%tClient Port:%t%t%9%n%nAdditional Information:%n%tTicket Options:%t%t%6%n%tTicket Encryption Type:%t%7%n%tFailure Code:%t%t%10%n%tTransited Services:%t%12%n%nThis event is generated every time access is requested to a resource such as a computer or a Windows service. The service name indicates the resource to which access was requested.%n%nThis event can be correlated with Windows logon events by comparing the Logon GUID fields in each event. The logon event occurs on the machine that was accessed, which is often a different machine than the domain controller which issued the service ticket.%n%nTicket options, encryption types, and failure codes are defined in RFC 4120.
0x2D6NTLM 身份验证失败,因为该帐户是“受保护用户”组的成员。%n%n帐户名称:%t%1%n设备名称:%t%2%n错误代码:%t%3 NTLM authentication failed because the account was a member of the Protected User group.%n%nAccount Name:%t%1%nDevice Name:%t%2%nError Code:%t%3
0x2D7NTLM 身份验证失败,因为需要访问控制限制。%n%n帐户名称:%t%1%n设备名称:%t%2%n错误代码:%t%3%n%n身份验证策略信息:%n%t接收器名称:%t%4%n%t策略名称:%t%5 NTLM authentication failed because access control restrictions are required.%n%nAccount Name:%t%1%nDevice Name:%t%2%nError Code:%t%3%n%nAuthentication Policy Information:%n%tSilo Name:%t%4%n%tPolicyName:%t%5
0x2D8通过使用 DES 或 RC4 进行 Kerberos 预身份验证失败,因为该帐户是“受保护用户”组的成员。%n%n帐户信息:%n%t安全 ID:%t%t%2%n%t帐户名称:%t%t%1%n%n服务信息:%n%t服务名称:%t%t%3%n%n网络信息:%n%t客户端地址:%t%t%7%n%t客户端端口:%t%t%8%n%n其他信息:%n%t票证选项:%t%t%4%n%t故障代码:%t%t%5%n%t预身份验证类型:%t%6%n%n证书信息:%n%t证书颁发者名称:%t%t%9%n%t证书序列号: %t%10%n%t证书指纹:%t%t%11%n%n仅当证书已用于预身份验证时才会提供证书信息。%n%n预身份验证类型、票证选项和故障代码是在 RFC 4120 中定义的。%n%n如果票证格式不正确或票证在传输期间损坏并且无法解密,则可能无法提供此事件中的许多字段。 Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.%n%nAccount Information:%n%tSecurity ID:%t%t%2%n%tAccount Name:%t%t%1%n%nService Information:%n%tService Name:%t%t%3%n%nNetwork Information:%n%tClient Address:%t%t%7%n%tClient Port:%t%t%8%n%nAdditional Information:%n%tTicket Options:%t%t%4%n%tFailure Code:%t%t%5%n%tPre-Authentication Type:%t%6%n%nCertificate Information:%n%tCertificate Issuer Name:%t%t%9%n%tCertificate Serial Number: %t%10%n%tCertificate Thumbprint:%t%t%11%n%nCertificate information is only provided if a certificate was used for pre-authentication.%n%nPre-authentication types, ticket options and failure codes are defined in RFC 4120.%n%nIf the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.
0x2D9用户访问远程桌面时被拒绝。默认情况下,用户只有在属于远程桌面用户组或管理员组的情况下才能连接。%n%n%t用户名:%t%1%n%t域:%t%t%2%n%t登录 ID:%t%3%n%t客户端地址:%t%4 A user was denied the access to Remote Desktop. By default, users are allowed to connect only if they are members of the Remote Desktop Users group or Administrators group.%n%n%tUser Name:%t%1%n%tDomain:%t%t%2%n%tLogon ID:%t%3%n%tClient Address:%t%4
0x2DE删除 SID 历史记录:%n%t目标帐户名称:%t%1%n%t目标域:%t%2%n%t目标帐户 ID:%t%3%n%t调用方用户名:%t%4%n%t调用方域:%t%5%n%t调用方登录 ID:%t%6%n%t特权:%t%7%n%tSidList:%t%8%n Remove SID History:%n%tTarget Account Name:%t%1%n%tTarget Domain:%t%2%n%tTarget Account ID:%t%3%n%tCaller User Name:%t%4%n%tCaller Domain:%t%5%n%tCaller Logon ID:%t%6%n%tPrivileges:%t%7%n%tSidList:%t%8%n
0x300检测到命名空间冲突:%n%t目标类型:%t%1%n%t目标名:%t%2%n%t林根:%t%3%n%t顶层名:%t%4%n%tDNS 名:%t%5%n%tNetBIOS 名:%t%6%n%tSID:%t%t%7%n%t新标记:%t%8%n Namespace collision detected:%n%tTarget type:%t%1%n%tTarget name:%t%2%n%tForest Root:%t%3%n%tTop Level Name:%t%4%n%tDNS Name:%t%5%n%tNetBIOS Name:%t%6%n%tSID:%t%t%7%n%tNew Flags:%t%8%n
0x301添加了受信任的林信息项:%n%t林根:%t%1%n%t林根 SID:%t%2%n%t操作 ID:%t{%3,%4}%n%t项类型:%t%5%n%t标记:%t%t%6%n%t顶层名:%t%7%n%tDNS 名:%t%8%n%tNetBIOS 名:%t%9%n%t域 SID:%t%10%n%t添加者%t:%n%t客户端用户名:%t%11%n%t客户端域:%t%12%n%t客户端登录 ID:%t%13%n Trusted Forest Information Entry Added:%n%tForest Root:%t%1%n%tForest Root SID:%t%2%n%tOperation ID:%t{%3,%4}%n%tEntry Type:%t%5%n%tFlags:%t%t%6%n%tTop Level Name:%t%7%n%tDNS Name:%t%8%n%tNetBIOS Name:%t%9%n%tDomain SID:%t%10%n%tAdded by%t:%n%tClient User Name:%t%11%n%tClient Domain:%t%12%n%tClient Logon ID:%t%13%n
0x302删除了受信任的林信息项:%n%t林根:%t%1%n%t林根 SID:%t%2%n%t操作 ID:%t{%3,%4}%n%t项类型:%t%5%n%t标记:%t%t%6%n%t顶层名:%t%7%n%tDNS 名:%t%8%n%tNetBIOS 名:%t%9%n%t域 SID:%t%10%n%t删除者%t:%n%t客户端用户名:%t%11%n%t客户端域:%t%12%n%t客户端登录 ID:%t%13%n Trusted Forest Information Entry Removed:%n%tForest Root:%t%1%n%tForest Root SID:%t%2%n%tOperation ID:%t{%3,%4}%n%tEntry Type:%t%5%n%tFlags:%t%t%6%n%tTop Level Name:%t%7%n%tDNS Name:%t%8%n%tNetBIOS Name:%t%9%n%tDomain SID:%t%10%n%tRemoved by%t:%n%tClient User Name:%t%11%n%tClient Domain:%t%12%n%tClient Logon ID:%t%13%n
0x303修改了受信任的林信息项:%n%t林根:%t%1%n%t林根 SID:%t%2%n%t操作 ID:%t{%3,%4}%n%t项类型:%t%5%n%t标记:%t%t%6%n%t顶层名:%t%7%n%tDNS 名:%t%8%n%tNetBIOS 名:%t%9%n%t域 SID:%t%10%n%t修改者%t:%n%t客户端用户名:%t%11%n%t客户端域:%t%12%n%t客户端登录 ID:%t%13%n Trusted Forest Information Entry Modified:%n%tForest Root:%t%1%n%tForest Root SID:%t%2%n%tOperation ID:%t{%3,%4}%n%tEntry Type:%t%5%n%tFlags:%t%t%6%n%tTop Level Name:%t%7%n%tDNS Name:%t%8%n%tNetBIOS Name:%t%9%n%tDomain SID:%t%10%n%tModified by%t:%n%tClient User Name:%t%11%n%tClient Domain:%t%12%n%tClient Logon ID:%t%13%n
0x304证书管理器拒绝了挂起的证书申请。%n%n请求 ID:%t%1 The certificate manager denied a pending certificate request.%n%nRequest ID:%t%1
0x305证书服务收到重新提交的证书申请。%n%n请求 ID:%t%1 Certificate Services received a resubmitted certificate request.%n%nRequest ID:%t%1
0x306证书服务吊销了证书。%n%n序列号:%t%1%n理由:%t%2 Certificate Services revoked a certificate.%n%nSerial No:%t%1%nReason:%t%2
0x307证书服务收到发行证书吊销列表(CRL) 的请求。%n%n下一次更新:%t%1%n发布 Base:%t%2%n发布 Delta:%t%3 Certificate Services received a request to publish the certificate revocation list (CRL).%n%nNext Update:%t%1%nPublish Base:%t%2%nPublish Delta:%t%3
0x308证书服务发行了证书吊销列表(CRL)。%n%nBase CRL:%t%1%nCRL 号:%t%t%2%n密钥容器:%t%3%n下一次发布:%t%4%n发布 URLs:%t%5 Certificate Services published the certificate revocation list (CRL).%n%nBase CRL:%t%1%nCRL No:%t%t%2%nKey Container:%t%3%nNext Publish:%t%4%nPublish URLs:%t%5
0x309更改了证书申请扩展。%n%n请求 ID:%t%1%n名称:%t%2%n类型:%t%3%n标记:%t%4%n数据:%t%5 A certificate request extension changed.%n%nRequest ID:%t%1%nName:%t%2%nType:%t%3%nFlags:%t%4%nData:%t%5
0x30A更改了多个证书申请属性。%n%n请求 ID:%t%1%n属性:%t%2 One or more certificate request attributes changed.%n%nRequest ID:%t%1%nAttributes:%t%2
0x30B证书服务收到关机请求。 Certificate Services received a request to shut down.
0x30C已开始证书服务备份。%n备份类型:%t%1 Certificate Services backup started.%nBackup Type:%t%1
0x30D已完成证书服务备份。 Certificate Services backup completed.
0x30E已开始证书服务还原。 Certificate Services restore started.
0x30F已完成证书服务还原。 Certificate Services restore completed.
0x310证书服务已经开始。%n%n证书数据库哈希:%t%1%n私钥使用计数:%t%2%nCA 证书哈希:%t%3%nCA 公钥哈希:%t%4 Certificate Services started.%n%nCertificate Database Hash:%t%1%nPrivate Key Usage Count:%t%2%nCA Certificate Hash:%t%3%nCA Public Key Hash:%t%4
0x311证书服务已经停止。%n%n证书数据库哈希:%t%1%n私钥使用计数:%t%2%nCA 证书哈希:%t%3%nCA 公钥哈希:%t%4 Certificate Services stopped.%n%nCertificate Database Hash:%t%1%nPrivate Key Usage Count:%t%2%nCA Certificate Hash:%t%3%nCA Public Key Hash:%t%4
0x312证书服务更改的安全权限。%n%n%1 The security permissions for Certificate Services changed.%n%n%1
0x313证书服务检索了存档密钥。%n%n请求 ID:%t%1 Certificate Services retrieved an archived key.%n%nRequest ID:%t%1
0x314证书服务将证书导入数据库中。%n%n证书:%t%1%n请求 ID:%t%2 Certificate Services imported a certificate into its database.%n%nCertificate:%t%1%nRequest ID:%t%2
0x315证书服务更改的审核筛选。%n%n筛选器:%t%1 The audit filter for Certificate Services changed.%n%nFilter:%t%1
0x316证书服务收到证书申请。%n%n请求 ID:%t%1%n请求者:%t%2%n属性:%t%3 Certificate Services received a certificate request.%n%nRequest ID:%t%1%nRequester:%t%2%nAttributes:%t%3
0x317证书服务批准了证书申请并颁发了证书。%n%n请求 ID:%t%1%n请求者:%t%2%n属性:%t%3%n部署:%t%4%nSKI:%t%t%5%n使用者:%t%6 Certificate Services approved a certificate request and issued a certificate.%n%nRequest ID:%t%1%nRequester:%t%2%nAttributes:%t%3%nDisposition:%t%4%nSKI:%t%t%5%nSubject:%t%6
0x318证书服务拒绝证书申请。%n%n请求 ID:%t%1%n请求者:%t%2%n属性:%t%3%n部署:%t%4%nSKI:%t%t%5%n使用者:%t%6 Certificate Services denied a certificate request.%n%nRequest ID:%t%1%nRequester:%t%2%nAttributes:%t%3%nDisposition:%t%4%nSKI:%t%t%5%nSubject:%t%6
0x319证书服务将证书申请状态设为挂起。%n%n请求 ID:%t%1%n请求者:%t%2%n属性:%t%3%n部署:%t%4%nSKI:%t%t%5%n使用者:%t%6 Certificate Services set the status of a certificate request to pending.%n%nRequest ID:%t%1%nRequester:%t%2%nAttributes:%t%3%nDisposition:%t%4%nSKI:%t%t%5%nSubject:%t%6
0x31A证书服务更改的证书管理器设置。%n%n启用:%t%1%n%n%2 The certificate manager settings for Certificate Services changed.%n%nEnable:%t%1%n%n%2
0x31B证书服务更改的配置项。%n%n节点:%t%1%n项目:%t%2%n值:%t%3 A configuration entry changed in Certificate Services.%n%nNode:%t%1%nEntry:%t%2%nValue:%t%3
0x31C证书服务更改属性。%n%n属性:%t%1%n索引:%t%2%n类型:%t%3%n值:%t%4 A property of Certificate Services changed.%n%nProperty:%t%1%nIndex:%t%2%nType:%t%3%nValue:%t%4
0x31D证书服务存档了密钥。%n%n请求 ID:%t%1%n请求者:%t%2%nKRA 哈希:%t%3 Certificate Services archived a key.%n%nRequest ID:%t%1%nRequester:%t%2%nKRA Hashes:%t%3
0x31E证书服务导入和存档了密钥。%n%n请求 ID:%t%1 Certificate Services imported and archived a key.%n%nRequest ID:%t%1
0x31F证书服务将 CA 证书发行到 Active Directory 域服务。%n%n证书哈希:%t%1%n有效从:%t%2%n有效至:%t%3 Certificate Services published the CA certificate to Active Directory Domain Services.%n%nCertificate Hash:%t%1%nValid From:%t%2%nValid To:%t%3
0x320从证书数据库删除一行或多行。%n%n表格 ID:%t%1%n筛选器:%t%2%n删除的行:%t%3 One or more rows have been deleted from the certificate database.%n%nTable ID:%t%1%nFilter:%t%2%nRows Deleted:%t%3
0x321角色分隔被启用:%t%1 Role separation enabled:%t%1
0x322证书服务模板:%n%1 v%2 (架构 V%3)%n%4%n%5%n%n域控制器:%t%6%n%n模板内容:%n%7%n安全描述符:%n%8 Certificate Services template:%n%1 v%2 (Schema V%3)%n%4%n%5%n%nDomain Controller:%t%6%n%nTemplate Content:%n%7%nSecurity Descriptor:%n%8
0x323更新的证书服务模板:%n%1 v%2 (架构 V%3)%n%4%n%5%n%n域控制器:%t%6%n%n旧模板内容:%n%8%n%n新模板内容:%n%7 Certificate Services template updated:%n%1 v%2 (Schema V%3)%n%4%n%5%n%nDomain Controller:%t%6%n%nOld Template Content:%n%8%n%nNew Template Content:%n%7
0x324安全更新的证书服务模板:%n%1 v%2 (架构 V%3)%n%4%n%5%n%n域控制器:%t%6%n%n旧模板内容:%n%9%n旧安全描述符:%n%10%n%n新模板内容:%n%7%n新安全描述符:%n%8 Certificate Services template security updated:%n%1 v%2 (Schema V%3)%n%4%n%5%n%nDomain Controller:%t%6%n%nOld Template Content:%n%9%nOld Security Descriptor:%n%10%n%nNew Template Content:%n%7%nNew Security Descriptor:%n%8
0x325此会话的安全日志的配置:%t日志大小上限 (KB): %1%n%t达到日志大小上限时的要采取的操作: %2%n%t事件存活时间限制天数: %3%n Configuration of security log for this session:%tMaximum Log Size (KB): %1%n%tAction to take on reaching max log size: %2%n%tEvent age limit in days: %3%n
0x326按用户审核策略表已经创建。%n%t元素的数量:%t%1%n%t策略 ID:%t%2%n Per User Audit Policy table created.%n%tNumber of elements:%t%1%n%tPolicy ID:%t%2%n
0x327按用户审核策略设置,用户:%n%t目标用户:%t%1%n%t策略 ID:%t%2%n%t类别设置:%n%t 系统:%t%3%n%t 登录:%t%4%n%t 对象访问%t%5%n%t 特权使用:%t%6%n%t 详细跟踪:%t%7%n%t 策略更改:%t%8%n%t 帐户管理:%t%9%n%t DS 访问:%t%10%n%t 帐户登录:%t%11%n Per user auditing policy set for user:%n%tTarget user:%t%1%n%tPolicy ID:%t%2%n%tCategory Settings:%n%t System:%t%3%n%t Logon:%t%4%n%t Object Access%t%5%n%t Privilege Use:%t%6%n%t Detailed Tracking:%t%7%n%t Policy Change:%t%8%n%t Account Management:%t%9%n%t DS Access:%t%10%n%t Account Logon:%t%11%n
0x328安全事件源已经试图注册。%n%t主用户名:%t%1%n%t主域:%t%2%n%t主登录 ID:%t%3%n%t客户端用户名:%t%4%n%t客户端域:%t%5%n%t客户端登录 ID:%t%6%n%t源名称:%t%7%n%t进程 Id:%t%8%n%t事件源 Id:%t%9%n%t映像文件名称:%t%10%n A security event source has attempted to register.%n%tPrimary User Name:%t%1%n%tPrimary Domain:%t%2%n%tPrimary Logon ID:%t%3%n%tClient User Name:%t%4%n%tClient Domain:%t%5%n%tClient Logon ID:%t%6%n%tSource Name:%t%7%n%tProcess Id:%t%8%n%tEvent Source Id:%t%9%n%tImage File Name:%t%10%n
0x329安全事件源已经试图注销。%n%t主用户名:%t%1%n%t主域:%t%2%n%t主登录 ID:%t%3%n%t客户端用户名:%t%4%n%t客户端域:%t%5%n%t客户端登录 ID:%t%6%n%t源名称:%t%7%n%t进程 Id:%t%8%n%t事件源 Id:%t%9%n%t映像文件名称:%t%10%n A security event source has attempted to unregister.%n%tPrimary User Name:%t%1%n%tPrimary Domain:%t%2%n%tPrimary Logon ID:%t%3%n%tClient User Name:%t%4%n%tClient Domain:%t%5%n%tClient Logon ID:%t%6%n%tSource Name:%t%7%n%tProcess Id:%t%8%n%tEvent Source Id:%t%9%n%tImage File Name:%t%10%n
0x32ACrashOnAuditFail 值已更改。%n%tCrashOnAuditFail 的新值:%t%1%n CrashOnAuditFail value has changed.%n%tNew value of CrashOnAuditFail:%t%1%n
0x32B对象的审核设置已更改:%n%t对象服务器:%t%1%n%t对象类型:%t%2%n%t对象名:%t%3%n%t句柄 ID:%t%4%n%t进程 ID:%t%5%n%t映像文件名:%t%6%n%n%t主要用户名:%t%7%n%t主域:%t%8%n%t主要登录 ID:%t%9%n%t客户端用户名:%t%10%n%t客户端域:%t%11%n%t客户端登录 ID:%t%12%n%t原安全描述符:%t%13%n%t新安全描述符:%t%14%n Auditing settings on object changed:%n%tObject Server:%t%1%n%tObject Type:%t%2%n%tObject Name:%t%3%n%tHandle ID:%t%4%n%tProcess ID:%t%5%n%tImage File Name:%t%6%n%n%tPrimary User Name:%t%7%n%tPrimary Domain:%t%8%n%tPrimary Logon ID:%t%9%n%tClient User Name:%t%10%n%tClient Domain:%t%11%n%tClient Logon ID:%t%12%n%tOriginal Security Descriptor:%t%13%n%tNew Security Descriptor:%t%14%n
0x32E特殊组登录表已创建。%n特殊组:%t%1%n Special Groups Logon table created.%nSpecial Groups:%t%1%n
0x330每用户审核策略更改:%n 用户:%t%t%1%n 类别:%t%2%n 子类别:%t%3%n 子类别 GUID:%t%4%n 更改:%t%5%n%n更改人:%n 用户名:%t%6%n 域名:%t%7%n 登录 ID:%t%8 Per User Audit Policy Change:%n User:%t%t%1%n Category:%t%2%n Sub Category:%t%3%n Sub Category Guid:%t%4%n Changes:%t%5%n%nChanged By:%n User Name:%t%6%n Domain Name:%t%7%n Logon ID:%t%8
0x340%t目标 DRA:%t%1%n%t源 DRA:%t%2%n%t源地址:%t%3%n%t命名上下文:%t%4%n%t选项:%t%5%n%t状态码:%t%6%n %tDestination DRA:%t%1%n%tSource DRA:%t%2%n%tSource Addr:%t%3%n%tNaming Context:%t%4%n%tOptions:%t%5%n%tStatus Code:%t%6%n
0x343%t目标 DRA:%t%1%n%t源 DRA:%t%2%n%t目标地址:%t%3%n%t命名上下文:%t%4%n%t选项:%t%5%n%t状态码:%t%6%n %tDestination DRA:%t%1%n%tSource DRA:%t%2%n%tDest. Addr:%t%3%n%tNaming Context:%t%4%n%tOptions:%t%5%n%tStatus Code:%t%6%n
0x344%t目标 DRA:%t%1%n%t源 DRA:%t%2%n%t命名上下文:%t%3%n%t选项:%t%4%n%t会话 ID:%t%5%n%t启动 USN:%t%6%n %tDestination DRA:%t%1%n%tSource DRA:%t%2%n%tNaming Context:%t%3%n%tOptions:%t%4%n%tSession ID:%t%5%n%tStart USN:%t%6%n
0x345%t目标 DRA:%t%1%n%t源 DRA:%t%2%n%t命名上下文:%t%3%n%t选项:%t%4%n%t会话 ID:%t%5%n%t结束 USN:%t%6%n%t状态码:%t%7%n %tDestination DRA:%t%1%n%tSource DRA:%t%2%n%tNaming Context:%t%3%n%tOptions:%t%4%n%tSession ID:%t%5%n%tEnd USN:%t%6%n%tStatus Code:%t%7%n
0x346%t会话 ID:%t%1%n%t对象:%t%2%n%t属性:%t%3%n%t更改的类型:%t%4%n%t新值:%t%5%n%tUSN:%t%6%n%t状态码:%t%7%n %tSession ID:%t%1%n%tObject:%t%2%n%tAttribute:%t%3%n%tType of change:%t%4%n%tNew Value:%t%5%n%tUSN:%t%6%n%tStatus Code:%t%7%n
0x347%t复制事件:%t%1%n%t审核状态码:%t%2%n %tReplication Event:%t%1%n%tAudit Status Code:%t%2%n
0x348%t复制事件:%t%1%n%t审核状态码:%t%2%n%t复制状态码:%t%3%n %tReplication Event:%t%1%n%tAudit Status Code:%t%2%n%tReplication Status Code:%t%3%n
0x349%t目标 DRA:%t%1%n%t源 DRA:%t%2%n%t对象:%t%3%n%t选项:%t%4%n%t状态码:%t%5%n %tDestination DRA:%t%1%n%tSource DRA:%t%2%n%tObject:%t%3%n%tOptions:%t%4%n%tStatus Code:%t%5%n
0x350Windows 防火墙启动时下列策略处于活动状态。%n%n应用的组策略: %1%n使用的配置文件: %2%n操作模式: %3%n允许远程管理: %4%n允许单播响应多波/广播流量: %5%n安全日志记录:%n 记录丢弃的数据包: %6%n 记录成功的连接 %7 The following policy was active when the Windows Firewall started.%n%nGroup Policy applied: %1%nProfile used: %2%nOperational mode: %3%nAllow remote administration: %4%nAllow unicast responses to multicast/broadcast traffic: %5%nSecurity Logging:%n Log dropped packets: %6%n Log successful connections %7
0x351Windows 防火墙启动时列出规则。%n%n使用的配置文件: %1%n规则:%n 规则 ID: %2%n 规则名称: %3 A rule was listed when the Windows Firewall started.%n%nProfile used: %1%nRule:%n Rule Id: %2%n Rule Name: %3
0x352已更改 Windows 防火墙例外列表。已添加规则。%n%n更改的配置文件: %1%n添加的规则:%n 规则 ID: %2%n 规则名称: %3 A change has been made to Windows Firewall exception list. A rule was added.%n%nProfile changed: %1%nAdded Rule:%n Rule Id: %2%n Rule Name: %3
0x353已更改 Windows 防火墙例外列表。已修改规则。%n%n更改的配置文件: %1%n修改的规则:%n 规则 ID: %2%n 规则名称: %3 A change has been made to Windows Firewall exception list. A rule was modified.%n%nProfile changed: %1%nModified Rule:%n Rule Id: %2%n Rule Name: %3
0x354已更改 Windows 防火墙例外列表。已删除规则。%n%n更改的配置文件: %1%n删除的规则:%n 规则 ID: %2%n 规则名称: %3 A change has been made to Windows Firewall exception list. A rule was deleted.%n%nProfile changed: %1%nDeleted Rule:%n Rule Id: %2%n Rule Name: %3
0x355已更改 Windows 防火墙设置。将设置还原为厂家默认值。%n A change has been made to Windows Firewall settings. Settings restored to factory defaults.%n
0x356Windows 防火墙设置已更改。%n%n更改的配置文件: %1%n新设置:%n 类型: %2%n 值: %3 A Windows Firewall setting has changed.%n%nProfile changed: %1%nNew Setting:%n Type: %2%n Value: %3
0x357规则已被忽略,因为 Windows 防火墙无法识别其主要版本号。%n%n配置文件: %1%n忽略的规则:%n ID:%2%n 名称:%3 A rule has been ignored because its major version number was not recognized by Windows Firewall.%n%nProfile: %1%nIgnored Rule:%n Id:%2%n Name:%3
0x358规则已被部分忽略,因为 Windows 防火墙无法识别其主要版本号。%n%n配置文件: %1%n部分忽略的规则:%n ID:%2%n 名称:%3 A rule has been partially ignored because its minor version number was not recognized by Windows Firewall.%n%nProfile: %1%nPartially Ignored Rule:%n Id:%2%n Name:%3
0x359规则已被 Windows 防火墙拒绝。%n%n配置文件: %1%n拒绝的原因:%2%n规则:%n ID:%3%n 名称:%4 A rule has been rejected by Windows Firewall.%n%nProfile: %1%nReason for Rejection:%2%nRule:%n Id:%3%n Name:%4
0x35A已经应用了 Windows 防火墙组策略设置。 Windows Firewall group policy settings have been applied.
0x35B已经删除了 Windows 防火墙组策略设置。 The Windows Firewall group policy settings have been removed.
0x35CWindows 防火墙已经切换了活动策略配置文件。%n%n活动配置文件: %1 The Windows Firewall has switched the active policy profile.%n%nActive profile: %1
0x35DWindows 防火墙未应用下列规则:%n规则:%n ID:%1%n 名称:%2%n原因: %3 解析为空集。 Windows Firewall did not apply the following rule:%nRule:%n Id:%1%n Name:%2%nReason: %3 resolved to an empty set.
0x35EWindows 防火墙未应用下列规则:%n规则:%n ID:%1%n 名称:%2%n错误: %3%n原因: %4 Windows Firewall did not apply the following rule:%nRule:%n Id:%1%n Name:%2%nError: %3%nReason: %4
0x360IPSec 入站数据包完整性检查失败:%n%t数据包源:%t%1%n%t入站 SA:%t%2%n%t数据包数量:%t%3%n从安全关联接收到数据完整性验证失败的数据包。这可能是临时出现的问题;如果此问题仍存在,则表明可能是网络条件不好,或者该数据包在中转到系统时被修改。%n IPSec inbound packet integrity check failed:%n%tPacket Source:%t%1%n%tInbound SA:%t%2%n%tNumber Of Packets:%t%3%nReceived packet from over a security association that failed data integrity verification. This could be a temporary problem; if it persists it may indicate either a poor network condition or that packets are being modified in transit to the system.%n
0x361IPSec 入站数据包重播检查失败:%n%t数据包源:%t%1%n%t入站 SA:%t%2%n %t数据包数量:%t%3%n从安全关联接收到数据包,而且数据包的序列号已被系统处理。这可能是临时出现的问题;如果此问题仍存在,则表明可能对系统有重播攻击。%n IPSec inbound packet replay check failed:%n%tPacket Source:%t%1%n%tInbound SA:%t%2%n %tNumber of Packets:%t%3%nReceived packet from over a security association with a sequence number for a packet already processed by the system.This could be a temporary problem; if it persists it may indicate a replay attack against the system.%n
0x362从安全关联接收到低序列号的数据包。IPsec 入站数据包重播检查失败。这表明可能有网络或硬件问题,或者正在进行重播攻击。请检查 IPsec 对等网络错误。若要检查重播攻击,请关闭对等设备并检查这些消息是否仍存在。如果消息仍存在,则表明可能有重播攻击。:%n%t数据包源:%t%1%n%t入站 SA:%t%2%n %t数据包数量:%t%3%n Received a packet over a security association with a low sequence number. IPsec inbound packet replay check failed.This may indicate a either network or hardware problem or that a replay attack is in process. Check your IPsec peer network for errors. To check for a replay attack shutdown the peer device and check if these messages persist. If the messages persist it may indicate a replay attack.:%n%tPacket Source:%t%1%n%tInbound SA:%t%2%n %tNumber of Packets:%t%3%n
0x363IPSec 接收到应该加密的入站明文包:%n%t包来源:%t%1%n%t入站 SA:%t%2%n%t包的数量:%t%3%n IPSec received inbound clear text packet that should have been secured:%n%tPacket Source:%t%1%n%tInbound SA:%t%2%n%tNumber of Packets:%t%3%n
0x364Windows 筛选平台阻止了数据包。:%n%t方向:%t%1%n%t本地地址:%t%2%n%t本地端口:%t%3%n%t远程地址:%t%4%n%t远程端口:%t%5%n%t协议:%t%6%n%t筛选器 LUID:%t%7%n%t层 ID:%t%8%n The Windows Filter Platform blocked a packet .:%n%tDirection:%t%1%n%tLocal Address:%t%2%n%tLocal Port:%t%3%n%tRemote Address:%t%4%n%tRemote Port:%t%5%n%tProtocol:%t%6%n%tFilter LUID:%t%7%n%tLayer Id:%t%8%n
0x365具有更多限制的 Windows 筛选平台筛选器阻止了数据包。:%n%t应用程序:%t%1%n%t方向:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t目标地址:%t%5%n%t目标端口:%t%6%n%t协议:%t%7%n%t筛选器运行时 ID:%t%8%n%t层:%t%9%n A more restrictive Windows Filtering Platform filter has blocked the packet.:%n%tApplication:%t%1%n%tDirection:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tDestination Address:%t%5%n%tDestination Port:%t%6%n%tProtocol:%t%7%n%tFilter run-time ID:%t%8%n%tLayer:%t%9%n
0x366Windows 筛选平台已允许应用程序或服务在端口上侦听传入连接。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t筛选器运行时 ID:%t%5%n%t层:%t%6%n Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tFilter run-time ID:%t%5%n%tLayer:%t%6%n
0x367Windows 筛选平台已阻止应用程序或服务在端口上侦听传入连接。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t筛选器运行时 ID:%t%5%n%t层:%t%6%n Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tFilter run-time ID:%t%5%n%tLayer:%t%6%n
0x368Windows 筛选平台已允许发生连接。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t协议:%t%5%n%t目标地址:%t%6%n%t目标端口:%t%7%n%t方向:%t%8%n%t筛选器运行时 ID:%t%9%n%t层:%t%10%n Windows Filtering Platform has permitted a connection to take place.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tProtocol:%t%5%n%tDestination Address:%t%6%n%tDestination Port:%t%7%n%tDirection:%t%8%n%tFilter run-time ID:%t%9%n%tLayer:%t%10%n
0x369Windows 筛选平台已阻止发生连接。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t协议:%t%5%n%t目标地址:%t%6%n%t目标端口:%t%7%n%t方向:%t%8%n%t筛选器运行时 ID:%t%9%n%t层:%t%10%n Windows Filtering Platform has blocked a connection from taking place.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tProtocol:%t%5%n%tDestination Address:%t%6%n%tDestination Port:%t%7%n%tDirection:%t%8%n%tFilter run-time ID:%t%9%n%tLayer:%t%10%n
0x36AWindows 筛选平台已允许绑定本地端口。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t协议:%t%5%n%t筛选器运行时 ID:%t%6%n%t层:%t%7%n Windows Filtering Platform has permitted a bind to a local port.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tProtocol:%t%5%n%tFilter run-time ID:%t%6%n%tLayer:%t%7%n
0x36BWindows 筛选平台已阻止绑定本地端口。:%n%t进程 ID:%t%1%n%t应用程序:%t%2%n%t源地址:%t%3%n%t源端口:%t%4%n%t协议:%t%5%n%t筛选器运行时 ID:%t%6%n%t层:%t%7%n Windows Filtering Platform has blocked a bind to a local port.:%n%tProcess ID:%t%1%n%tApplication:%t%2%n%tSource Address:%t%3%n%tSource Port:%t%4%n%tProtocol:%t%5%n%tFilter run-time ID:%t%6%n%tLayer:%t%7%n
0x36D特殊组已分配给令牌:%n%t用户 SID:%t%1%n%t用户名:%t%2%n%t域:%t%t%3%n%t登录 ID:%t%t%4%n%t登录 GUID:%t%5%n%t已分配的特殊组:%t%6%n%t调用方用户名:%t%7%n%t调用方域:%t%8%n%t调用方登录 ID:%t%9%n%t调用方登录 GUID:%t%10%n Special groups have been assigned to a token:%n%tUser Sid:%t%1%n%tUser Name:%t%2%n%tDomain:%t%t%3%n%tLogon ID:%t%t%4%n%tLogon GUID:%t%5%n%tSpecial Groups assigned:%t%6%n%tCaller User Name:%t%7%n%tCaller Domain:%t%8%n%tCaller Logon ID:%t%9%n%tCaller Logon Guid:%t%10%n
0x370在 IPSec 主模式 SA 协商期间,IKE/Authip 接收到无效的 ISAKMP 数据包。这表明可能是网络条件不好,或者尝试修改或重播此协商。本地地址: %1%n远程地址: %2%n端本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n During IPSec main mode SA negotiation, IKE/Authip received an invalid ISAKMP packet. This could indicate a poor network condition or an attempt to modify or replay this negotiation.Local address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%n
0x371在 IPSec 快速模式 SA 协商期间,IKE/Authip 接收到无效的 ISAKMP 数据包。这表明可能是网络条件不好,或者尝试修改或重播此协商。本地地址: %1%n本地地址掩码: %2%n远程地址: %3%n远程地址掩码: %4%n本地端口: %5%n远程端口: %6%n协议: %7%n封装类型: %8%n During IPSec quick mode SA negotiation, IKE/Authip received an invalid ISAKMP packet. This could indicate a poor network condition or an attempt to modify or replay this negotiation.Local address: %1%nLocal address mask: %2%nRemote address: %3%nRemote address mask: %4%nLocal port: %5%nRemote port: %6%nProtocol: %7%nEncapsulation type: %8%n
0x372在 IPSec 用户模式 SA 协商期间,Authip 接收到无效的 ISAKMP 数据包。这表明可能是网络条件不好,或者尝试修改或重播此协商。本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n During IPSec user mode SA negotiation, Authip received an invalid ISAKMP packet. This could indicate a poor network condition or an attempt to modify or replay this negotiation.Local address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%n
0x373已建立 IPSec 主模式和用户模式安全关联。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n主模式身份验证方法: %6%n主模式我的 ID: %7%n主模式对等端 ID: %8%n密码算法: %9%n完整性算法: %10%n生存时间(秒): %11%n主模式模拟: %12%n主模式 SA LUID: %13%n%n用户模式身份验证方法: %14%n用户模式我的 ID: %15%n用户模式对等端 ID: %16%n用户模式模拟: %17%n IPSec main mode and user mode security associations established.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nMain mode authentication method: %6%nMain mode my Id: %7%nMain mode Peer Id: %8%nCipher algorithm: %9%nIntegrity algorithm: %10%nLifetime (seconds): %11%nMain mode impersonation: %12%nMain mode SA LUID: %13%n%nUser mode authentication method: %14%nUser mode my Id: %15%nUser mode peer Id: %16%nUser mode impersonation: %17%n
0x374已建立 IPSec 主模式和用户模式安全关联。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n主模式身份验证方法: %6%n主模式我的 ID: %7%n主模式对等端 ID: %8%n密码算法: %9%n完整性算法: %10%n生存时间(秒): %11%n主模式模拟: %12%n主模式 SA LUID: %13%n%n用户模式身份验证方法: %14%n用户模式对等端使用者: %n%15%n用户模式对等端发布证书颁发机构: %n%16%n用户模式对等端根证书颁发机构: %n%17%n用户模式对等端 SHA 指纹: %n%18%n用户模式我的使用者: %n%19%n用户模式我的 SHA 指纹: %n%20%n用户模式模拟: %21%n IPSec main mode and user mode security associations established.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nMain mode authentication method: %6%nMain mode my Id: %7%nMain mode peer Id: %8%nCipher algorithm: %9%nIntegrity algorithm: %10%nLifetime (seconds): %11%nMain mode impersonation: %12%nMain mode SA LUID: %13%n%nUser mode authentication method: %14%nUser mode peer subject: %n%15%nUser mode peer issuing certificate authority: %n%16%nUser mode peer root certificate authority: %n%17%nUser mode peer SHA thumbprint: %n%18%nUser mode my subject: %n%19%nUser mode my SHA thumbprint: %n%20%nUser mode impersonation: %21%n
0x375已建立 IPSec 主模式和用户模式安全关联。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n主模式身份验证方法: %6%n主模式对等使用者: %n%7%n主模式对等发布证书颁发机构: %n%8%n主模式对等根证书颁发机构: %n%9%n主模式对等 SHA 指纹: %n%10%n主模式我的使用者: %n%11%n主模式我的 SHA 指纹: %n%12%n密码算法: %13%n完整性算法: %14%n生存时间(秒): %15%n主模式模拟: %16%n主模式 SA LUID: %17%n%n用户模式身份验证方法: %18%n用户模式我的 ID: %19%n用户模式对等端 ID: %20%n用户模式模拟: %21%n IPSec main mode and user mode security associations established.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nMain mode authentication method: %6%nMain mode peer subject: %n%7%nMain mode peer issuing certificate authority: %n%8%nMain mode peer root certificate authority: %n%9%nMain mode peer SHA thumbprint: %n%10%nMain mode my subject: %n%11%nMain mode my SHA thumbprint: %n%12%nCipher algorithm: %13%nIntegrity algorithm: %14%nLifetime (seconds): %15%nMain mode impersonation: %16%nMain mode SA LUID: %17%n%nUser mode authentication method: %18%nUser mode my Id: %19%nUser mode peer Id: %20%nUser mode impersonation: %21%n
0x376已建立 IPSec 主模式和用户模式安全关联。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n主模式身份验证方法: %6%n主模式对等使用者: %n%7%n主模式对等发布证书颁发机构: %n%8%n主模式对等根证书颁发机构: %n%9%n主模式对等 SHA 指纹: %n%10%n主模式我的使用者: %n%11%n主模式我的 SHA 指纹: %n%12%n密码算法: %13%n完整性算法: %14%n生存时间(秒): %15%n主模式模拟: %16%n主模式 SA LUID: %17%n%n用户模式身份验证方法: %18%n用户模式对等端使用者: %n%19%n用户模式对等端发布证书颁发机构: %n%20%n用户模式对等端根证书颁发机构: %n%21%n用户模式对等端 SHA 指纹: %n%22%n用户模式我的使用者: %n%23%n用户模式我的 SHA 指纹: %n%24%n用户模式模拟: %25%n IPSec main mode and user mode security associations established.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nMain mode authentication method: %6%nMain mode peer subject: %n%7%nMain mode peer issuing certificate authority: %n%8%nMain mode peer root certificate authority: %n%9%nMain mode peer SHA thumbprint: %n%10%nMain mode my subject: %n%11%nMain mode my SHA thumbprint: %n%12%nCipher algorithm: %13%nIntegrity algorithm: %14%nLifetime (seconds): %15%nMain mode impersonation: %16%nMain mode SA LUID: %17%n%nUser mode authentication method: %18%nUser mode peer subject: %n%19%nUser mode peer issuing certificate authority: %n%20%nUser mode peer root certificate authority: %n%21%nUser mode peer SHA thumbprint: %n%22%nUser mode my subject: %n%23%nUser mode my SHA thumbprint: %n%24%nUser mode impersonation: %25%n
0x377IPSec 用户模式安全关联建立失败。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n用户模式身份验证方法: %6%n用户模式对等端使用者: %n%7%n用户模式对等端发布证书颁发机构: %n%8%n用户模式对等端根证书颁发机构: %n%9%n用户模式对等端 SHA 指纹: %n%10%n用户模式我的使用者: %n%11%n用户模式我的 SHA 指纹: %n%12%n故障点: %13%n故障原因: %14%n用户模式 IKE 状态: %15%n发起程序或响应程序: %16%n用户模式模拟: %17%n IPSec user mode security association establishment failed.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nUser mode authentication method: %6%nUser mode peer subject: %n%7%nUser mode peer issuing certificate authority: %n%8%nUser mode peer root certificate authority: %n%9%nUser mode peer SHA thumbprint: %n%10%nUser mode my subject: %n%11%nUser mode my SHA thumbprint: %n%12%nFailure point: %13%nFailure reason: %14%nUser mode IKE state: %15%nInitiator or Responder: %16%nUser mode impersonation: %17%n
0x378IPSec 用户模式安全关联建立失败。%n密钥模块类型: AuthIp%n本地地址: %1%n远程地址: %2%n本地端口: %3%n远程端口: %4%n对等端专用地址: %5%n用户模式身份验证方法: %6%n用户模式我的 ID: %7%n用户模式对等端 ID: %8%n故障点: %9%n故障原因: %10%n用户模式 IKE 状态: %11%n发起程序或响应程序: %12%n用户模式模拟: %13%n IPSec user mode security association establishment failed.%nKeying module type: AuthIp%nLocal address: %1%nRemote address: %2%nLocal port: %3%nRemote port: %4%nPeer private address: %5%nUser mode authentication method: %6%nUser mode my Id: %7%nUser mode peer Id: %8%nFailure point: %9%nFailure reason: %10%nUser mode IKE state: %11%nInitiator or Responder: %12%nUser mode impersonation: %13%n
0x3A0Windows 防火墙服务已成功启动。 The Windows Firewall Service has successfully started.
0x3A1Windows 防火墙服务已停止。 The Windows Firewall Service has been stopped.
0x3A3Windows 防火墙无法从本地存储中检索安全策略。Windows 防火墙将继续实施当前实施的策略。%n错误代码: %1 The Windows Firewall was unable to retrieve the security policy from the local storage. The Windows Firewall will continue enforcing the current enforced policy.%nError Code: %1
0x3A4Windows 防火墙无法解析新安全策略。Windows 防火墙将继续当前实施的策略。%n错误代码: %1 The Windows Firewall was unable to parse the new security policy. The Windows Firewall will continue with currently enforced policy.%nError Code: %1
0x3A5Windows 防火墙无法初始化驱动程序。Windows 防火墙将继续实施当前策略。%n错误代码: %1 The Windows Firewall failed to initialize the driver. The Windows Firewall will continue to enforce current policy.%nError Code: %1
0x3A6Windows 防火墙服务无法启动。%n错误代码: %1 The Windows Firewall service failed to start.%nError Code: %1
0x3A7Windows 防火墙服务在关闭期间发现错误。%n错误代码: %1 The Windows Firewall service found errors during shutdown.%nError Code: %1
0x3A8Windows 防火墙服务发现关键运行时错误。正在终止。%n错误代码: %1 The Windows Firewall service found a critical runtime error. Terminating.%nError Code: %1
0x3A9Windows 防火墙驱动程序已成功启动。 The Windows Firewall Driver has successfully started.
0x3AAWindows 防火墙驱动程序已停止。 The Windows Firewall Driver has been stopped.
0x3ABWindows 防火墙驱动程序无法启动。%n错误代码: %1 The Windows Firewall Driver failed to start.%nError Code: %1
0x3ACWindows 防火墙驱动程序在关闭期间发现错误。%n错误代码: %1 The Windows Firewall Driver found errors during shutdown.%nError Code: %1
0x3ADWindows 防火墙驱动程序发现关键运行时错误。正在终止。%n错误代码: %1 The Windows Firewall Driver found critical runtime error. Terminating.%nError Code: %1
0x3B0已更改 IPSec 设置。已添加身份验证集。%n%n更改的配置文件: %1%n添加的身份验证集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. An Authentication Set was added.%n%nProfile changed: %1%nAdded Authentication Set:%n Id: %2%n Name: %3
0x3B1已更改 IPSec 设置。已修改身份验证集。%n%n更改的配置文件: %1%n修改的身份验证集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. An Authentication Set was modified.%n%nProfile changed: %1%nModified Authentication Set:%n Id: %2%n Name: %3
0x3B2已更改 IPSec 设置。已删除身份验证集。%n%n更改的配置文件: %1%n删除的身份验证集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. An Authentication Set was deleted.%n%nProfile changed: %1%nDeleted Authentication Set:%n Id: %2%n Name: %3
0x3B3已更改 IPSec 设置。已添加连接安全规则。%n%n更改的配置文件: %1%n添加的连接安全规则:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Connection Security Rule was added.%n%nProfile changed: %1%nAdded Connection Security Rule:%n Id: %2%n Name: %3
0x3B4已更改 IPSec 设置。已修改连接安全规则。%n%n更改的配置文件: %1%n修改的连接安全规则:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Connection Security Rule was modified.%n%nProfile changed: %1%nModified Connection Security Rule:%n Id: %2%n Name: %3
0x3B5已更改 IPSec 设置。已删除连接安全规则。%n%n更改的配置文件: %1%n删除的连接安全规则:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Connection Security Rule was deleted.%n%nProfile changed: %1%nDeleted Connection Security Rule:%n Id: %2%n Name: %3
0x3B6已更改 IPSec 设置。已添加加密集。%n%n更改的配置文件: %1%n添加的加密集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Crypto Set was added.%n%nProfile changed: %1%nAdded Crypto Set:%n Id: %2%n Name: %3
0x3B7已更改 IPSec 设置。已修改加密集。%n%n更改的配置文件: %1%n修改的加密集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Crypto Set was modified.%n%nProfile changed: %1%nModified Crypto Set:%n Id: %2%n Name: %3
0x3B8已更改 IPSec 设置。已删除加密集。%n%n更改的配置文件: %1%n删除的加密集:%n ID: %2%n 名称: %3 A change has been made to IPSec settings. A Crypto Set was deleted.%n%nProfile changed: %1%nDeleted Crypto Set:%n Id: %2%n Name: %3
0x3B9已删除 IPSec 安全关联。%n%n更改的配置文件: %1%n删除的 SA:%n ID: %2%n 名称: %3 An IPSec Security Association was deleted.%n%nProfile changed: %1%nDeleted SA:%n Id: %2%n Name: %3
0x3BA未更新 IPSec 策略,因为无法到达 Active Directory 域服务。%n The IPSec policy was not updated because Active Directory Domain Services could not be reached.%n
0x3D0Windows 筛选平台基本筛选引擎启动时,出现下列标注。%n%n提供程序 ID:%t%1%n提供程序名称:%t%2%n标注 ID:%t%3%n标注名称:%t%4%n标注类型:%t%5%n标注运行时 ID:%t%6%n层 ID:%t%7%n层名称:%t%8%n层运行时 ID:%t%9 The following callout was present when the Windows Filtering Platform Base Filtering Engine started.%n%nProvider ID:%t%1%nProvider name:%t%2%nCallout ID:%t%3%nCallout name:%t%4%nCallout type:%t%5%nCallout run-time ID:%t%6%nLayer ID:%t%7%nLayer name:%t%8%nLayer run-time ID:%t%9
0x3D1Windows 筛选平台基本筛选引擎启动时,出现下列筛选器。%n%n提供程序 ID:%t%1%n提供程序名称:%t%2%n筛选器 ID:%t%3%n筛选器名称:%t%4%n筛选器类型:%t%5%n筛选器运行时 ID:%t%6%n层 ID:%t%7%n层名称:%t%8%n层运行时 ID:%t%9%n权重:%t%10%n%n条件:%t%11%n筛选器操作:%t%12%n标注 ID:%t%13%n标注名称:%t%14 The following filter was present when the Windows Filtering Platform Base Filtering Engine started.%n%nProvider ID:%t%1%nProvider name:%t%2%nFilter ID:%t%3%nFilter name:%t%4%nFilter type:%t%5%nFilter run-time ID:%t%6%nLayer ID:%t%7%nLayer name:%t%8%nLayer run-time ID:%t%9%nWeight:%t%10%n%nConditions:%t%11%nFilter Action:%t%12%nCallout ID:%t%13%nCallout name:%t%14
0x3D2Windows 筛选平台基本筛选引擎启动时,出现下列提供程序。%n%n提供程序 ID:%t%1%n提供程序名称:%t%2%n提供程序类型:%t%3 The following provider was present when the Windows Filtering Platform Base Filtering Engine started.%n%nProvider ID:%t%1%nProvider name:%t%2%nProvider type:%t%3
0x3D3Windows 筛选平台基本筛选引擎启动时,出现下列提供程序上下文。%n%n提供程序 ID:%t%1%n提供程序名称:%t%2%n提供程序上下文 ID:%t%3%n提供程序上下文名称:%t%4%n提供程序上下文类型:%t%5 The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.%n%nProvider ID:%t%1%nProvider name:%t%2%nProvider context ID:%t%3%nProvider context name:%t%4%nProvider context type:%t%5
0x3D4Windows 筛选平台基本筛选引擎启动时,出现下列子层。%n%n提供程序 ID:%t%1%n提供程序名称:%t%2%n子层 ID:%t%3%n子层名称:%t%4%n子层类型:%t%5%n权重:%t%6 The following sublayer was present when the Windows Filtering Platform Base Filtering Engine started.%n%nProvider ID:%t%1%nProvider name:%t%2%nSublayer ID:%t%3%nSublayer name:%t%4%nSublayer type:%t%5%nWeight:%t%6
0x3D6已更改 Windows 筛选平台标注。%n%n进程 ID:%t%1%n用户 ID:%t%2%n用户名:%t%3%n提供程序 ID:%t%4%n提供程序名称:%t%5%n更改类型:%t%6%n标注 ID:%t%7%n标注名称:%t%8%n标注类型:%t%9%n标注运行时 ID:%t%10%n层 ID:%t%11%n层名称:%t%12%n层运行时 ID:%t%13 A Windows Filtering Platform callout has been changed.%n%nProcess ID:%t%1%nUser ID:%t%2%nUser name:%t%3%nProvider ID:%t%4%nProvider name:%t%5%nChange type:%t%6%nCallout ID:%t%7%nCallout name:%t%8%nCallout type:%t%9%nCallout run-time ID:%t%10%nLayer ID:%t%11%nLayer name:%t%12%nLayer run-time ID:%t%13
0x3D7已更改 Windows 筛选平台筛选器。%n%n进程 ID:%t%1%n用户 ID:%t%2%n用户名:%t%3%n提供程序 ID:%t%4%n提供程序名称:%t%5%n更改类型:%t%6%n筛选器 ID:%t%7%n筛选器名称:%t%8%n筛选器类型:%t%9%n筛选器运行时 ID:%t%10%n层 ID:%t%11%n层名称:%t%12%n层运行时 ID:%t%13%n权重:%t%14%n%n条件:%t%15%n筛选器操作:%t%16%n标注 ID:%t%17%n标注名称:%t%18 A Windows Filtering Platform filter has been changed.%n%nProcess ID:%t%1%nUser ID:%t%2%nUser name:%t%3%nProvider ID:%t%4%nProvider name:%t%5%nChange type:%t%6%nFilter ID:%t%7%nFilter name:%t%8%nFilter type:%t%9%nFilter run-time ID:%t%10%nLayer ID:%t%11%nLayer name:%t%12%nLayer run-time ID:%t%13%nWeight:%t%14%n%nConditions:%t%15%nFilter Action:%t%16%nCallout ID:%t%17%nCallout name:%t%18
0x3D8已更改 Windows 筛选平台提供程序。%n%n进程 ID:%t%1%n用户 ID:%t%2%n用户名:%t%3%n更改类型:%t%4%n提供程序 ID:%t%5%n提供程序名称:%t%6%n提供程序类型:%t%7 A Windows Filtering Platform provider has been changed.%n%nProcess ID:%t%1%nUser ID:%t%2%nUser name:%t%3%nChange type:%t%4%nProvider ID:%t%5%nProvider name:%t%6%nProvider type:%t%7
0x3D9已更改 Windows 筛选平台提供程序上下文。%n%n进程 ID:%t%1%n用户 ID:%t%2%n用户名:%t%3%n提供程序 ID:%t%4%n提供程序名称:%t%5%n更改类型:%t%6%n提供程序上下文 ID:%t%7%n提供程序上下文名称:%t%8%n提供程序上下文类型:%t%9 A Windows Filtering Platform provider context has been changed.%n%nProcess ID:%t%1%nUser ID:%t%2%nUser name:%t%3%nProvider ID:%t%4%nProvider name:%t%5%nChange type:%t%6%nProvider context ID:%t%7%nProvider context name:%t%8%nProvider context type:%t%9
0x3DA已更改 Windows 筛选平台子层。%n%n进程 ID:%t%1%n用户 ID:%t%2%n用户名:%t%3%n提供程序 ID:%t%4%n提供程序名称:%t%5%n更改类型:%t%6%n子层 ID:%t%7%n子层名称:%t%8%n子层类型:%t%9%n权重:%t%10 A Windows Filtering Platform sublayer has been changed.%n%nProcess ID:%t%1%nUser ID:%t%2%nUser name:%t%3%nProvider ID:%t%4%nProvider name:%t%5%nChange type:%t%6%nSublayer ID:%t%7%nSublayer name:%t%8%nSublayer type:%t%9%nWeight:%t%10
0x3E0已建立 IPsec 快速模式安全关联。%n%n本地地址:%t%1%n本地地址掩码:%t%2%n本地端口:%t%3%n本地隧道终结点:%t%4%n远程地址:%t%5%n远程地址掩码:%t%6%n远程端口:%t%7%n远程专用地址:%t%8%n远程隧道终结点:%t%9%n协议:%t%10%n密钥模块名称:%t%11%n完整性算法 - AH:%t%12%n完整性算法 - ESP:%t%13%n加密算法:%t%14%n生存时间 - 秒:%t%15%n生存时间 - 数据:%t%16%n生存时间 - 数据包:%t%17%n模式:%t%18%n角色:%t%19%n快速模式筛选器标识符:%t%20%n主模式 SA 标识符:%t%21%n快速模式 SA 标识符:%t%22%n入站 SPI:%t%23%n出站 SPI:%t%24 An IPsec Quick Mode security association was established.%n%nLocal address:%t%1%nLocal address mask:%t%2%nLocal port:%t%3%nLocal tunnel endpoint:%t%4%nRemote address:%t%5%nRemote address mask:%t%6%nRemote port:%t%7%nRemote private address:%t%8%nRemote tunnel endpoint:%t%9%nProtocol:%t%10%nKeying module name:%t%11%nIntegrity algorithm - AH:%t%12%nIntegrity algorithm - ESP:%t%13%nEncryption algorithm:%t%14%nLifetime - seconds:%t%15%nLifetime - data:%t%16%nLifetime - packets:%t%17%nMode:%t%18%nRole:%t%19%nQuick Mode filter identifier:%t%20%nMain Mode SA identifier:%t%21%nQuick Mode SA identifier:%t%22%nInbound SPI:%t%23%nOutbound SPI:%t%24
0x3E1已结束 IPsec 快速模式安全关联。%n%n本地地址:%t%1%n本地端口:%t%2%n本地隧道终结点:%t%3%n远程地址:%t%4%n远程端口:%t%5%n远程隧道终结点:%t%6%n协议:%t%7%n快速模式 SA 标识符:%t%8 An IPsec Quick Mode security association ended.%n%nLocal address:%t%1%nLocal port:%t%2%nLocal tunnel endpoint:%t%3%nRemote address:%t%4%nRemote port:%t%5%nRemote tunnel endpoint:%t%6%nProtocol:%t%7%nQuick Mode SA identifier:%t%8
0x3E2IPsec 与远程计算机的协商失败,因为未启动 IKE 和 AuthIP IPsec 密钥模块(IKEEXT)服务。 An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started.
0x400已启动 OCSP 响应程序服务。 OCSP Responder Service Started.
0x401已停止 OCSP 响应程序服务。 OCSP Responder Service Stopped.
0x402已更改 OCSP 响应程序服务中的配置项。%nCA 配置 ID: %t%1%n新值: %t%2%n A Configuration entry changed in OCSP Responder Service.%nCA Configuration ID: %t%1%nNew Value: %t%2%n
0x403已更改 OCSP 响应程序服务中的配置项。%nPropertyName: %t%1%n新值: %t%2%n A Configuration entry changed in OCSP Responder Service.%nPropertyName: %t%1%nNew Value: %t%2%n
0x404已更新 OCSP 响应程序服务上的安全设置。%n新值:%t%1%n Security setting is updated on OCSP Responder Service.%nNew Value:%t%1%n
0x405将请求提交到 OCSP 响应程序服务。%n A request is submitted to OCSP Responder Service.%n
0x406OCSP 响应程序服务自动更新签名证书。%nCA 配置 ID: %t%1%n新签名证书哈希: %t%2%n Signing Certificate is automatically updated by OCSP Responder Service.%nCA Configuration ID: %t%1%nNew Signing Certificate Hash: %t%2%n
0x407OCSP 吊销提供程序已成功更新吊销信息。%nCA 配置 ID: %t%1%n基本 CRL 号: %t%2%n基本 CRL 此更新: %t%3%n基本 CRL 哈希: %t%4%n增量 CRL 号: %t%5%n增量 CRL 指示器: %t%6%n增量 CRL 此更新: %t%7%n增量 CRL 哈希: %t%8%n OCSP Revocation Provider successfully updated the revocation information.%nCA Configuration ID: %t%1%nBase CRL Number: %t%2%nBase CRL This Update: %t%3%nBase CRL Hash: %t%4%nDelta CRL Number: %t%5%nDelta CRL Indicator: %t%6%nDelta CRL This Update: %t%7%nDelta CRL Hash: %t%8%n
0xFFF最高系统-定义的审核消息值。 Highest System-Defined Audit Message Value.

EXIF

File Name:msaudite.dll.mui
Directory:%WINDIR%\WinSxS\amd64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_10.0.15063.0_zh-cn_ca9fe79a79ccfa47\
File Size:90 kB
File Permissions:rw-rw-rw-
File Type:Win32 DLL
File Type Extension:dll
MIME Type:application/octet-stream
Machine Type:Intel 386 or later, and compatibles
Time Stamp:0000:00:00 00:00:00
PE Type:PE32
Linker Version:14.10
Code Size:0
Initialized Data Size:91136
Uninitialized Data Size:0
Entry Point:0x0000
OS Version:10.0
Image Version:10.0
Subsystem Version:6.0
Subsystem:Windows GUI
File Version Number:10.0.15063.0
Product Version Number:10.0.15063.0
File Flags Mask:0x003f
File Flags:(none)
File OS:Windows NT 32-bit
Object File Type:Dynamic link library
File Subtype:0
Language Code:Chinese (Simplified)
Character Set:Unicode
Company Name:Microsoft Corporation
File Description:安全审核事件 DLL
File Version:10.0.15063.0 (WinBuild.160101.0800)
Internal Name:msaudite.dll
Legal Copyright:© Microsoft Corporation. All rights reserved.
Original File Name:msaudite.dll.mui
Product Name:Microsoft® Windows® Operating System
Product Version:10.0.15063.0
Directory:%WINDIR%\WinSxS\wow64_microsoft-windows-m..ditevtlog.resources_31bf3856ad364e35_10.0.15063.0_zh-cn_d4f491ecae2dbc42\

What is msaudite.dll.mui?

msaudite.dll.mui is Multilingual User Interface resource file that contain Chinese (Simplified) language for file msaudite.dll (安全审核事件 DLL).

File version info

File Description:安全审核事件 DLL
File Version:10.0.15063.0 (WinBuild.160101.0800)
Company Name:Microsoft Corporation
Internal Name:msaudite.dll
Legal Copyright:© Microsoft Corporation. All rights reserved.
Original Filename:msaudite.dll.mui
Product Name:Microsoft® Windows® Operating System
Product Version:10.0.15063.0
Translation:0x804, 1200