Share via

Security Event ID 5152 by the thousands

Anonymous
2009-06-15T16:35:00+00:00

Windows Vista Business 32-bit SP1 build 6.0.6001.  The Security Auditing Log is filling with thousands of identical events every hour.  The event id is 5152.

Log Name:      Security

Source:        Microsoft-Windows-Security-Auditing

Date:          6/15/2009 12:01:04 PM

Event ID:      5152

Task Category: Filtering Platform Packet Drop

Level:         Information

Keywords:      Audit Failure

User:          N/A

Computer:      D4J96D1.corp.trexlerhainesgas.com

Description:

The Windows Filtering Platform blocked a packet.

Application Information:

 Process ID:  0

 Application Name: -

Network Information:

 Direction:  Outbound

 Source Address:  192.168.0.112

 Source Port:  0

 Destination Address: 192.168.0.112

 Destination Port:  0

 Protocol:  1

Filter Information:

 Filter Run-Time ID: 65870

 Layer Name:  ICMP Error

 Layer Run-Time ID: 32

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

  <System>

    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />

    <EventID>5152</EventID>

    <Version>0</Version>

    <Level>0</Level>

    <Task>12809</Task>

    <Opcode>0</Opcode>

    <Keywords>0x8010000000000000</Keywords>

    <TimeCreated SystemTime="2009-06-15T16:01:04.395Z" />

    <EventRecordID>2702755</EventRecordID>

    <Correlation />

    <Execution ProcessID="4" ThreadID="60" />

    <Channel>Security</Channel>

    <Computer>D4J96D1.corp.trexlerhainesgas.com</Computer>

    <Security />

  </System>

  <EventData>

    <Data Name="ProcessId">0</Data>

    <Data Name="Application">-</Data>

    <Data Name="Direction">%%14593</Data>

    <Data Name="SourceAddress">192.168.0.112</Data>

    <Data Name="SourcePort">0</Data>

    <Data Name="DestAddress">192.168.0.112</Data>

    <Data Name="DestPort">0</Data>

    <Data Name="Protocol">1</Data>

    <Data Name="FilterRTID">65870</Data>

    <Data Name="LayerName">%%14601</Data>

    <Data Name="LayerRTID">32</Data>

  </EventData>


tsmith

Windows for home | Previous Windows versions | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

  1. Anonymous
    2009-06-15T22:37:05+00:00

    Hi tsmiththi,

    Thanks for using the Community Forums for Microsoft Vista.

    It looks very much like a virus\trojan.

    I would run scans to make sure that it is or is not that.

    Take a look at this “sticky” to learn more about some useful tools to check your computer.

    Please let us know if we can do anything else for you.


    Matt

    Microsoft Answers Support Engineer

    Visit our Microsoft Answers Feedback Forum and let us know what you think.

    0 comments No comments

6 additional answers

Sort by: Most helpful
  1. Anonymous
    2010-07-19T09:14:34+00:00

    I'm facing the same too, anyway to resolve this?

    run windows 2008 + AD, and outbound internet traffic will encountered the same error

    0 comments No comments
  2. Anonymous
    2009-06-16T18:29:48+00:00

    Sorry, yes.  This machine is a member of an Active Directory domain in our small business. 


    tsmith

    0 comments No comments
  3. Anonymous
    2009-06-16T00:26:43+00:00

    Are you on a Domain?


    Matt

    Microsoft Answers Support Engineer

    Visit our Microsoft Answers Feedback Forum and let us know what you think.

    0 comments No comments
  4. Anonymous
    2009-06-16T00:12:22+00:00

    We are running Trend-Micro Worry-Free Business Security Advanced, and my machine was just scanned with the 6/14 definition updates.  I will download and run sysinterals rootkit scanner as well.


    tsmith

    0 comments No comments