NEED SOME HELP
PC was running high so I checked my event viewer. I do not think this was the problem, but it is odd to me!
Maybe it is normal
Thanks
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 5/17/2011 6:19:13 AMEvent ID: 4905
Task Category: Audit Policy Change
Level: Information
Keywords: Audit Success
User: N/A
Computer: ********-PC
Description:
An attempt was made to unregister a security event source.
Subject
Security ID: SYSTEM
Account Name: *******-PC$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Process:
Process ID: 0x470
Process Name: C:\Windows\System32\VSSVC.exe
Event Source:
Source Name: VSSAudit
Event Source ID: 0x7cec0d
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>4905</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>13568</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2011-05-17T10:19:13.867Z" />
<EventRecordID>167</EventRecordID>
<Correlation />
<Execution ProcessID="692" ThreadID="836" />
<Channel>Security</Channel>
<Computer>*******-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">******-PC$</Data>
<Data Name="SubjectDomainName">WORKGROUP</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="AuditSourceName">VSSAudit</Data>
<Data Name="EventSourceId">0x7cec0d</Data>
<Data Name="ProcessId">0x470</Data>
<Data Name="ProcessName">C:\Windows\System32\VSSVC.exe</Data>
</EventData>
</Event>
THIS WAS BEFORE
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 5/17/2011 6:18:14 AMEvent ID: 4672
Task Category: Special Logon
Level: Information
Keywords: Audit Success
User: N/A
Computer: ******-PC
Description:
Special privileges assigned to new logon.
Subject:
Security ID: SYSTEM
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Privileges: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>4672</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12548</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2011-05-17T10:18:14.041Z" />
<EventRecordID>165</EventRecordID>
<Correlation />
<Execution ProcessID="692" ThreadID="1852" />
<Channel>Security</Channel>
<Computer>*******-PC</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">SYSTEM</Data>
<Data Name="SubjectDomainName">NT AUTHORITY</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege</Data>
</EventData>
</Event>