suspicios activity logons advapi

48807390 20 Reputation points
2023-04-11T10:41:14.69+00:00

hello i have bunch of successfull logons in security logs on windows 10 they looks like this and repeat frequently even if i dont do anything

"Login to the account has been completed successfully. Subject: Security ID: S-1-5-18 Account name: TESTWIN10_CHGIK$ Account domain: CHGIK Input ID: 0x3E7 Login Information: Input type: 5 Limited Administration Mode: - Virtual Account: No Extended Token: Yes Impersonation Level: Impersonation New entry: Security ID: S-1-5-18 Account Name: SYSTEM Account domain: NT AUTHORITY Input ID: 0x3E7 Associated Login ID: 0x0 Network Account Name: - Network account domain: - Input GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x2ac Process name: C:\Windows\System32\services.exe Network Information: Workstation name: - Source network address: - Source port: - Authentication Details: Login Process: Advapi Authentication Package: Negotiate Intermediate Services: - Package name (NTLM only): - Key length: 0

it this ok? should i do something that stop generating this messages? i saw some threads on internet about this but nobody said usefull information except that it might be something in scheluder but how i cant debut what is it?

Windows for business | Windows Client for IT Pros | Devices and deployment | Configure application groups
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.