Windows 10: Events 4672 & 4624 Win 10 Freezes - special LOGON ?

Discus and support Events 4672 & 4624 Win 10 Freezes - special LOGON ? in AntiVirus, Firewalls and System Security to solve the problem; My window 10 machine continues to freeze for 5-30 seconds intermittently. [ATTACH] I am running with an boot drive on an M2 SSD, which seems to... Discussion in 'AntiVirus, Firewalls and System Security' started by AUSTNAARON, Jan 17, 2019.

  1. Events 4672 & 4624 Win 10 Freezes - special LOGON ?


    My window 10 machine continues to freeze for 5-30 seconds intermittently.



    Events 4672 & 4624 Win 10 Freezes  - special LOGON ? 44988f5c-7a34-4f03-b814-35e806617496?upload=true.png


    I am running with an boot drive on an M2 SSD, which seems to be a common thread of most people having this issue.


    I have already done the SFC scan, and the reset/validation of all system files. didn't fix it.


    It's a brand new win 10 / 64 bit install.


    So... how do I resolve this? I've attached the event records that were generated at the time of the event below.

    ''''''''''''''''''''

    - System
    -
    Provider
    [ Name] Microsoft-Windows-Security-Auditing
    [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}
    EventID 4672
    Version 0
    Level 0
    Task 12548
    Opcode 0
    Keywords 0x8020000000000000
    - TimeCreated
    [ SystemTime] 2019-01-17T13:18:33.562408900Z
    EventRecordID 37510
    - Correlation
    [ ActivityID] {b7b4670b-ac8e-0003-1b67-b4b78eacd401}
    - Execution
    [ ProcessID] 968
    [ ThreadID] 1080
    Channel Security
    Computer DESKTOP-2UPSH75
    Security
    -
    EventData

    SubjectUserSid S-1-5-18
    SubjectUserName SYSTEM
    SubjectDomainName NT AUTHORITY
    SubjectLogonId 0x3e7
    PrivilegeList SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege


    ================================


    - System

    - Provider
    [ Name] Microsoft-Windows-Security-Auditing
    [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}
    EventID 4624
    Version 2
    Level 0
    Task 12544
    Opcode 0
    Keywords 0x8020000000000000
    - TimeCreated
    [ SystemTime] 2019-01-17T13:11:32.382839600Z
    EventRecordID 37507
    - Correlation
    [ ActivityID] {b7b4670b-ac8e-0003-1b67-b4b78eacd401}
    - Execution
    [ ProcessID] 968
    [ ThreadID] 7424
    Channel Security
    Computer DESKTOP-2UPSH75
    Security
    -
    EventData

    SubjectUserSid S-1-5-18
    SubjectUserName DESKTOP-2UPSH75$
    SubjectDomainName WORKGROUP
    SubjectLogonId 0x3e7
    TargetUserSid S-1-5-18
    TargetUserName SYSTEM
    TargetDomainName NT AUTHORITY
    TargetLogonId 0x3e7
    LogonType 5
    LogonProcessName Advapi
    AuthenticationPackageName Negotiate
    WorkstationName -
    LogonGuid {00000000-0000-0000-0000-000000000000}
    TransmittedServices -
    LmPackageName -
    KeyLength 0
    ProcessId 0x398
    ProcessName C:\Windows\System32\services.exe
    IpAddress -
    IpPort -
    ImpersonationLevel %%1833
    RestrictedAdminMode -
    TargetOutboundUserName -
    TargetOutboundDomainName -
    VirtualAccount %%1843
    TargetLinkedLogonId 0x0
    ElevatedToken %%1842

    :)
     
    AUSTNAARON, Jan 17, 2019
    #1
  2. lukeaar Win User

    Windows 10 - Alert Sound played every few minutes corresponding to Event ID 4624, 4672

    Every three-ish minutes, my windows 10 machine plays an alert sound. After annoying me for a couple of weeks, I've finally found that the sound corresponds to two Security events logged in the event viewer (I have replaced my computer name with COMPUTER_NAME).

    The first is a 4624 Logon event as follows:

    An account was successfully logged on.

    Subject:

    Security ID: SYSTEM

    Account Name: COMPUTER_NAME$

    Account Domain: WORKGROUP

    Logon ID: 0x3E7

    Logon Information:

    Logon Type: 5

    Restricted Admin Mode: -

    Virtual Account: No

    Elevated Token: Yes

    Impersonation Level: Impersonation

    New Logon:

    Security ID: SYSTEM

    Account Name: SYSTEM

    Account Domain: NT AUTHORITY

    Logon ID: 0x3E7

    Linked Logon ID: 0x0

    Network Account Name: -

    Network Account Domain: -

    Logon GUID: {00000000-0000-0000-0000-000000000000}

    Process Information:

    Process ID: 0x2f8

    Process Name: C:\Windows\System32\services.exe

    Network Information:

    Workstation Name:

    Source Network Address: -

    Source Port: -

    Detailed Authentication Information:

    Logon Process: Advapi

    Authentication Package: Negotiate

    Transited Services: -

    Package Name (NTLM only): -

    Key Length: 0

    The second 4672 event is as follows:

    Special privileges assigned to new logon.

    Subject:

    Security ID: SYSTEM

    Account Name: SYSTEM

    Account Domain: NT AUTHORITY

    Logon ID: 0x3E7

    Privileges: SeAssignPrimaryTokenPrivilege

    SeTcbPrivilege

    SeSecurityPrivilege

    SeTakeOwnershipPrivilege

    SeLoadDriverPrivilege

    SeBackupPrivilege

    SeRestorePrivilege

    SeDebugPrivilege

    SeAuditPrivilege

    SeSystemEnvironmentPrivilege

    SeImpersonatePrivilege

    It seems that this is a service running every couple of minutes. Why am I getting an alert sound every time? I can't find anything in Task Scheduler to explain these events.

    Instead of just muting sounds and ignoring it, I'd like to fix the problem properly. Any thoughts?
     
    lukeaar, Jan 17, 2019
    #2
  3. Peeg Win User
    windows 8.1 is executing winsat.exe automatically even though its disabled in task scheduler.

    windows 8.1 is executing winsat.exe automatically even though its disabled in task scheduler. When Checking event viewer security logs it tells me someone logged into my computer even though I was already logged in but idle and executed winsat.exe. Is this normal or is someone logging into my computer remotely? I have multiple logins and special logins in my Log and logoffs when i did not logoff.

    Audit Success 6/29/2014 5:29:03 PM Microsoft Windows security auditing. 4616 Security State Change
    Audit Success 6/29/2014 5:03:25 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 5:03:25 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:13:16 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 2:13:16 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:03:54 PM Microsoft Windows security auditing. 4634 Logoff
    Audit Success 6/29/2014 2:03:54 PM Microsoft Windows security auditing. 4634 Logoff
    Audit Success 6/29/2014 2:00:18 PM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 2:00:18 PM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 2:00:18 PM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 2:00:18 PM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 2:00:15 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 2:00:15 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:00:15 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:00:15 PM Microsoft Windows security auditing. 4648 Logon
    Audit Success 6/29/2014 2:00:07 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 2:00:07 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 2:00:07 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:00:07 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 2:00:07 PM Microsoft Windows security auditing. 4648 Logon
    Audit Success 6/29/2014 2:00:06 PM Microsoft Windows security auditing. 4647 Logoff
    Audit Success 6/29/2014 12:55:51 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 12:55:51 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 12:43:02 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 12:43:02 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 12:43:02 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 12:43:02 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 12:16:13 PM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 12:16:13 PM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:20:53 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:20:53 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:19:04 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:19:04 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:09:04 AM Microsoft Windows security auditing. 6406 Other System Events
    Audit Success 6/29/2014 11:07:59 AM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 11:07:59 AM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 11:07:59 AM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 11:07:59 AM Microsoft Windows security auditing. 4797 User Account Management
    Audit Success 6/29/2014 11:07:57 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:57 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:56 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:56 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:56 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:56 AM Microsoft Windows security auditing. 4648 Logon
    Audit Success 6/29/2014 11:07:50 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:50 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:48 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:48 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:45 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:45 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:45 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:44 AM Microsoft Windows security auditing. 5024 Other System Events
    Audit Success 6/29/2014 11:07:44 AM Microsoft Windows security auditing. 5033 Other System Events
    Audit Success 6/29/2014 11:07:44 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:44 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4648 Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4672 Special Logon
    Audit Success 6/29/2014 11:07:42 AM Microsoft Windows security auditing. 4624 Logon
     
  4. Events 4672 & 4624 Win 10 Freezes - special LOGON ?

    SPECIAL LOGON in Event Log

    Hi Emeline,

    Thank you for posting the query on Microsoft Community.

    • When you say special logon, what are you referring to?
    • What do you mean by private browser window?

    Refer the link below for more information about event logs or viewer:

    Event
    viewer-- What is going on in your computer


    Please get back to us with the required information to assist you further.
     
    Kalpana Shankarappa, Jan 17, 2019
    #4
Thema:

Events 4672 & 4624 Win 10 Freezes - special LOGON ?

Loading...
  1. Events 4672 & 4624 Win 10 Freezes - special LOGON ? - Similar Threads - Events 4672 4624

  2. Security Auditing ID: 4624/4672 Special Logon and Logon

    in Windows 10 Gaming
    Security Auditing ID: 4624/4672 Special Logon and Logon: Hello, Im constantly getting this audit success every 5-10 minutes. I need help on what this is, and how can I fix it, because it freezes my computer like hardlock and goes back to normal. Here is both events Views. First is Special Logon and Second is LogonSPECIAL...
  3. Security Auditing ID: 4624/4672 Special Logon and Logon

    in Windows 10 Software and Apps
    Security Auditing ID: 4624/4672 Special Logon and Logon: Hello, Im constantly getting this audit success every 5-10 minutes. I need help on what this is, and how can I fix it, because it freezes my computer like hardlock and goes back to normal. Here is both events Views. First is Special Logon and Second is LogonSPECIAL...
  4. Are Special Logons Suspicious? Event id: 4672

    in AntiVirus, Firewalls and System Security
    Are Special Logons Suspicious? Event id: 4672: Hello, I've noticed multiple different "special logon" events event id: 4672 wherein some of the events have different privileges than others. Is this normal? some of the privileges were:SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege,...
  5. Are Special Logons Suspicious? Event id: 4672

    in Windows 10 Gaming
    Are Special Logons Suspicious? Event id: 4672: Hello, I've noticed multiple different "special logon" events event id: 4672 wherein some of the events have different privileges than others. Is this normal? some of the privileges were:SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege,...
  6. Are Special Logons Suspicious? Event id: 4672

    in Windows 10 Software and Apps
    Are Special Logons Suspicious? Event id: 4672: Hello, I've noticed multiple different "special logon" events event id: 4672 wherein some of the events have different privileges than others. Is this normal? some of the privileges were:SeSecurityPrivilege, SeTakeOwnershipPrivilege, SeLoadDriverPrivilege, SeBackupPrivilege,...
  7. Continuous freezing - event viewer showing floods of 5379 as well as periodic 4672, 4624, 4798

    in Windows 10 BSOD Crashes and Debugging
    Continuous freezing - event viewer showing floods of 5379 as well as periodic 4672, 4624, 4798: Processor: IntelR CoreTM i3-2350M CPU @ 2.30GHz 2.30 GHz 64-bit operating system, x64-based processor RAM: 8.00 GB Edition: Windows 10 Home Version: 20H2 OS Build: 19042.662 Experience: Windows Feature Experience Pack 120.2212.551.0 My 2012 HP G6-series laptop has...
  8. Event 4672, Special Logon

    in AntiVirus, Firewalls and System Security
    Event 4672, Special Logon: Why would this event be shown in my logs. No one else has had access or been given access to my pc. I will attach the event records: Log Name: Security Source: Microsoft-Windows-Security-Auditing Date: 12/3/2019 3:55:00 AM Event ID: 4672...
  9. Microsoft Windows Security Auditing Event 4624 Followed By Event 4672 Crashes Games

    in Windows 10 Gaming
    Microsoft Windows Security Auditing Event 4624 Followed By Event 4672 Crashes Games: I have recently been having an issue where I'll be playing Rainbow Six Seige and the game will close at random. When the game closes (when I'm in the middle of playing it) there is no crash report and no report in the Application section of Event Viewer. But, when I go to the...
  10. Event 4672 & 4624 & 5379 PC Freezing

    in Windows 10 BSOD Crashes and Debugging
    Event 4672 & 4624 & 5379 PC Freezing: I have had this for a while now but it seems to have gotten worse recently. My PC has been freezing (1-4 seconds every hour or so) and the only thing that I can tie in is these Events happening at the same time as the freeze all the time. Events 4672 (Special privileges...

Users found this page by searching for:

  1. 4672 special logon event crashes graphics driver

    ,
  2. Special Logon 4672

    ,
  3. windows event 4624 freeze