Event Type: SuccessAudit Event Source: Quest File Access Audit Source Event Category: Local Access Event ID: 4610 Date: 10/28/2009 Time: 10:48:53 User: NT AUTHORITY\SYSTEM Computer: SERVER Description: Shadow copy created: Primary User Name: SYSTEM Primary User Domain: NT AUTHORITY Client User Name: Client User Domain: User Logon ID: (0x0,0x3E7) Process: C:\WINDOWS\system32\svchost.exe Volume Path: C: Shadow copy: 10/28/2009 10:48:40 AM