Event Details
Operating System->Microsoft Windows->Built-in logs->Windows 2000-2003->Security Log->Account Management->EventID 642 - User Account Changed [Win 2000 / XP]
EventID 642 - User Account Changed [Win 2000 / XP]
Indicates that a user account ("target account") was successfully changed by another user ("caller user"). If a property changed, the new value is specified. Properties that display hyphens did not change.

Find more information about this event on ultimatewindowssecurity.com.
    Corresponding events on other OS versions:
    Windows 2003 Windows 2008
     Sample:
            Event Type:     Success Audit
            Event Source:   Security
            Event Category: Account Management
            Event ID:       642
            Date:           11/13/2009
            Time:           11:32:59
            User:           LOGISTICS\ALebovsky
            Computer:       DCCC1
            Description:
            User Account Changed:
            -
            Target Account Name:	Paul
            Target Domain:	LOGISTICS
            Target Account ID:	%{S-1-5-21-746137067-343818398-839522115-1143}
            Caller User Name:	ALebovsky
            Caller Domain:	LOGISTICS
            Caller Logon ID:	(0x0,0x416355)
            Privileges:	-
          
    Log Type: Windows Event Log
     Uniquely Identified By:
    Log Name: Security
    Filtering Field Equals to Value
    OSVersion Windows 2000
    Windows XP
    Category Account Management
    Source Security
    EventId 642
    Field Matching
    FieldDescriptionStored inSample Value
    DateTime Date/Time of event origination in GMT format. DateTime 10.10.2000 19:00:00
    Source Name of an Application or System Service originating the event. Source Security
    Type Warning, Information, Error, Success, Failure, etc. Type Success
    User Domain\Account name of user/service/computer initiating event. User RESEARCH\Alebovsky
    Computer Name of server workstation where event was logged. Computer DC1
    EventID Numerical ID of event. Unique within one Event Source. EventId 576
    Description The entire unparsed event message. Description Special privileges assigned to new logon.
    Log Name The name of the event log (e.g. Application, Security, System, etc.) LogName Security
    Category A name for a subclass of events within the same Event Source. Category Logon/Logoff
    Caller User Name Account initiating action InsertionString5 ALebovsky
    Caller Domain Domain of the account initiating action InsertionString6 LOGISTICS
    Caller Logon ID A number uniquely identifying the logon session of the user initiating action. This number can be used to correlate all user actions within one logon session. InsertionString7 (0x0,0x416355)
    User Account Changed Displays details of the change InsertionString1
    Target Account Name Name of the account on which the action is performed InsertionString2 Paul
    Target Domain Domain name of the Target Account InsertionString3 LOGISTICS
    Target Account ID Target Account Name in the following format: Target Domain\Target Account Name InsertionString4 %{S-1-5-21-746137067-343818398-839522115-1143}
    Privileges Contains the list of privileges. The purpose of this field is unknown. In most cases it is empty. InsertionString8 -
    Comments
    You must be logged in to comment