Computer crashes microsoft windows security audit event id 4624.

Hi all.. Im having some problems with my computer hanging while I listen to music these days... I looked in the Windows Event Viewer and that's what I found with the corresponding times. It's only annoying of any help that you can suggest would be great. I'm using Windows 7 64 bit

Error description:
An account has been connected successfully.

Object:
Security ID: SYSTEM
Account name: MATT-PC$
Domain account: WORKING group
Logon ID: 0x3e7

Logon type: 5

New logon:
Security ID: SYSTEM
Account name: SYSTEM
Account domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process information:
Process ID: 0 x 204
Process name: C:\Windows\System32\services.exe

Network information:
Name of the workstation:
Source network address: -.
Source port: -.

Detailed authentication information:
Logon process: Advapi
Authentication package: negotiate
Transited Services: -.
Package Name (NTLM only): -.
Key length: 0

This event is generated when a session is created. It is generated on the computer that was consulted.

The fields of the object indicate the account on the local system that requested the opening of session. It is more often a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the type of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The new session fields indicate the account for which the new logon was created, which is the account that was logged.

The network fields indicate where source opening of remote session request. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information on this specific logon request.
-Connection GUID is a unique identifier that can be used to correlate this event with a KDC event.
-Transit services indicate which intermediate services participated in this logon request.
-Name of the package indicates what auxiliary Protocol was used among the NTLM protocols.
-Key length indicates the length of the generated session key. This will be 0 if no session key was requested.

Details

-< system="">
  < provider="" name=" Microsoft-Windows-Security-Auditing " guid=" {54849625-5478-4994-A5BA-3E3B0328C30D} ">
  < eventid="">4624
  < version="">0
  < level="">0
  < task="">12544
  < opcode="">0
  < keywords="">0 x 8020000000000000
  < timecreated="" systemtime=" 2009-12-10T00:50:23.253155100Z ">
  < eventrecordid="">9073
  < correlation="">
  < execution="" processid=" 540 " threadid=" 1596 ">
  < channel="">Security
  < computer="">mast - PC
  < security="">
 

-< eventdata="">
  < data="" name=" SubjectUserSid ">S-1-5-18
  < data="" name=" SubjectUserName ">MATT-PC$
  < data="" name=" SubjectDomainName ">WORKING GROUP
  < data="" name=" SubjectLogonId ">0x3e7
  < data="" name=" TargetUserSid ">S-1-5-18
  < data="" name=" TargetUserName ">SYSTEM
  < data="" name=" TargetDomainName ">NT AUTHORITY
  < data="" name=" TargetLogonId ">0x3e7
  < data="" name=" LogonType ">5
  < data="" name=" LogonProcessName ">Advapi
  < data="" name=" AuthenticationPackageName ">Negotiate
  < data="" name=" WorkstationName ">
  < data="" name=" LogonGuid ">{00000000-0000-0000-0000-000000000000}
  < data="" name=" TransmittedServices ">-
  < data="" name=" LmPackageName ">-
  < data="" name=" KeyLength ">0
  < data="" name=" ProcessId ">0 x 204
  < data="" name=" ProcessName ">C:\Windows\System32\services.exe
  < data="" name=" IpAddress ">-

Thank you for any information you can provide... im a noob when it comes to such things.

Hi Mkress,

Welcome!

You can get this error if Windows Error Reporting Service does not start, try to restart the service on the computer and check if the problem persists or not, follow the steps below to start the service:

1. click on start.

2 type Services in the start search.

3. look for Windows Error Reporting Service in the list.

4. right click on the Service.

5. click on properties.

6. set the Startup Type to automatic.

7 set the starting state.

8. click on apply.

9. click on OK.

Now restart the computer for the changes to the effect.

I would say that you do the check disk on the computer to find the bad sectors and disk related errors on the computer, follow these steps:

1. the procedure for chkdsk to run:

i. Click Start

II. type cmd in the start search box.

III. right-click on cmd.exe list programs and then select the run as Administrator option.

IV. If you are prompted for an administrator password or for confirmation, type your password, or click on continue.

v. in the command prompt window, type the following command and press enter Chkdsk/r

Note: When you restart, Windows checks the drive for errors, and then Windows starts. Now, run the disk check in the command prompt.

Swathi B - Microsoft technical support.
Visit our
Microsoft answers feedback Forum and let us know what you think.

Tags: Windows

Similar Questions

  • Audit failure Microsoft Windows security. 4625 login

    Passe spent Review Journal windows 2008 r2, that is windows 7 from two computers constantly try to start the session. I spent the antivirus, antispyware, malware, etc and detect any virus, Trojan horse, worm, on computers. You can help resolve makes these applications and how to eliminate.

    The port is changing from 50 to 65000. the log message attached

    Thank you

    Failure of 29/05/2013 audit audit 08:53:02 Microsoft Windows security. 4625 login

    Failure of 29/05/2013 audit audit 08:50:32 Microsoft Windows security. 4625 login

    Error on the login account.

    Object:

    Security ID: NULL SID

    Account name: -.

    Account domain: -.

    Logon ID: 0x0

    Logon type 3

    The typical error log:

    Security ID: NULL SID

    Account name: MARIA-PC $

    Account domain: VFM1

    Error information:

    Reason for the failure: unknown username or bad password

    Status: 0xc000006d

    Subreport: 0xc0000064

    Process information:

    Caller process ID: 0x0

    The name of the calling process: -.

    Information network:

    The workstation name: MARY-PC

    Source network address: 192.168.1.207

    Port: 50506

    Detailed authentication information:

    Logon process: NtLmSsp

    Authentication package: NTLM

    Transited Services: -.

    Package Name (NTLM only): -.

    Key length: 0

    Hi Javier,

    The question you posted would be better suited in the TechNet Forums since we have dedicated to this support; We recommend that you post your question in the TechNet Forums to get help:

    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

    Keep us updated on the status of the issue.

  • computer crashed, have windows vista, indented leave, all the documents lost, can I get all the files, how do

    computer crashed, have windows vista, indented leave, all the documents lost, can I get all the files, how to do it, in simple terms,

    Thank you.

    If by "computer of new beginning" you mean that you have started your recovery or disk restore factory set and reinstalled Windows, then the ability to recover your files is practically zero.  You can try a utility like Recuva (http://www.piriform.com/recuva) but since you have rewritten the entire hard drive, it is highly unlikely that anything will be recoverable.

  • Spybot Search Destroy & detected "microsoft.windows.security.internet Explorer.

    What is MICROSOFT. WINDOWS. SECURITY. INTERNET EXPLORE Spybot search & destroy found the file. Can I remove or ignore.

    You will find in favour of Spybot in these forums: http://forums.spybot.info/

    Tip: microsoft.windows.security.internet explore is an NNTP address for it now interrupted (on MS newserver) security IE specific newsgroup, always available via some package newsservers & Google groups, but there is nothing but spam messages now => http://groups.google.com/group/microsoft.public.internetexplorer.security

  • How to fix my computer crashing whenever windows is an automatic update?

    Whenever my computer did an automatic update of windows and automatically restarts my computer crashes and I have to open in safe mood so he can go back on.

    How can I fix it?

    Assuming that McAfee Security Center is NOT yet installed:

    McAfee (and Norton) applications are notorious for not not upgrade (or uninstalling) itself.

    1. download the McAfee Consumer Product Removal, save it to your desktop tool: http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe

    2. close all open applications (that is, anything with an icon on the taskbar).

    3. right click on the file that you saved in #1 above and select run as administrator to run the utility. DO TAP not your keyboard until the race ends, then restart.

    4. do a clean install of McAfee Security Center.

    -Online if you purchased your software directly from McAfee, go to https://home.mcafee.com/Secure/Protected/Login.aspx to connect and download your software.

    -Online DELL users should go to https://us.mcafee.com/root/login.asp?affid=105

    5 IMPORTANT! Manually & repeatedly updated McAfee Security Center until you get a "not more than updated" or similar prompt.

    6. open Internet Explorer (only) to http://support.microsoft.com/kb/923737 & run the difficulty.

    7. now, open Internet Explorer (only) to http://support.microsoft.com/kb/971058 & race that secure it in modes AGGRESSIVE then by DEFAULT. [1]

    8 restart a last time & test.

    ~~~~~~~~~~~~~~~~~~~~~~~~
    [1] full Disclosure: the difficulty operating in AGGRESSIVE mode will remove your update history but not the list of installed updates.

  • I received a phone call from a man by the name of Thomson. He said that I was risking to have my computer crash. My security proovider is AVG and they say my computers are save.

    Received phone call from a man named Thomson.  He said he was with Windows in the United States and Florida.   Was given the phone number of 315-506-4544.  Asking for help with problems with my computer detected by Windows.  He said that I was risking my computer and overwriting of files.  Very difficult to understand.  He asked I right click on my computer and highlight all the files with any questions.  I didn't trust this person so I hung up the phone.  I continued to return calls 4 - 5 times.  This doesn't seem to be a legitimate caller.  My security proovider is AVG and they say my computers are recording to date.  Was it a bogus scam

    Hello

    Its as SCAM!

    The number is either usurped or re-directec to another number or even another country.

    -506 (315) - 4544
    http://www.numberinvestigator.com/phone/315-506-4544.html

    Avoid scams to phone for tech support
    http://www.Microsoft.com/security/online-privacy/avoid-phone-scams.aspx

    In the United States, you can contact the FBI, Attorney general, the police authorities and consumer
    Watch groups. Arm yourself with knowledge.

    The Internet Crime Complaint Center (IC3) is a partnership between the Federal Bureau of Investigation
    (FBI) and the National White Collar Crime Center (NW3C), funded in part by the Bureau of Justice Assistance
    (BJA).
    http://www.ic3.gov/complaint/default.aspx

    No, Microsoft wouldn't you not solicited. Or they would know if errors exist on your
    computer. So that's the fraud or scams to get your money or worse to steal your identity.

    Avoid scams that use the Microsoft name fraudulently - Microsoft is not unsolicited
    phone calls to help you fix your computer
    http://www.Microsoft.com/protect/fraud/phishing/msName.aspx

    Scams and hoaxes
    http://support.Microsoft.com/contactus/cu_sc_virsec_master?ws=support#tab3

    Microsoft Support Center consumer
    https://consumersecuritysupport.Microsoft.com/default.aspx?altbrand=true&SD=GN&ln=en-us&St=1&wfxredirect=1&gssnb=1

    Microsoft technical support
    http://support.Microsoft.com/contactus/?ws=support#TAB0

    Microsoft - contact technical support
    http://Windows.Microsoft.com/en-us/Windows/help/contact-support

    I hope this helps.

    Rob Brown - Microsoft MVP<- profile="" -="" windows="" expert="" -="" consumer="" :="" bicycle="" -="" mark="" twain="" said="" it="">

  • Get a Microsoft-Windows-Kernel-Power event ID 41 error

    * Original title: Event Id 41

    Okay, I need help in a while now, I've got the same errow:

    Lognavn: System
    Quiet: Microsoft-Windows-Kernel-Power
    Dato: 02/07/2015-20:47:21
    Haendelses-id: 41
    Opgavekategori (63) (63).
    Level: Kritisk
    Nogleord (2) (2).
    Bruger: SYSTEM
    Computer: oliver
    Beskrivelse:
    Preferential har genstartet uden at lukke ned town forst. Denne r. kan LED to preferential er op holdt med to svare, er gaet ned, eller at Strømmen forsvandt uventet.
    Haendelses-Xml:

     
       
        41
        3
        1
        63
        0
        0 x 8000000000000002
       
        56325
       
       
        System
        oliverc1234
       
     

     
        209
        0xffffd0002a830000
        0x2
        0 x 0
        0xfffff800503b5353
        0
        0
        0
     

    and I did what I could do, but it keeps coming up any ideas what I can to provent to come again?

    Hi Oliver,.

    Sorry for the late reply and I appreciate your patience.

    The kernel power event 41 ID error occurs when the computer is off or it restarts unexpectedly. Starting a computer that is running Windows, a check is made to determine if the computer has been properly closed. If the computer was not closed properly, a kernel Power event 41 message is generated.

    I suggest you to consult the article below the link https://support.microsoft.com/kb/2028504?wa=wsignin1.0 and check if it helps.

    Please do not answer with others and we will be happy to help you.

  • MMO to laptop computer crash caused Windows updates

    Okay, I had problems with an MMO, and they said for me to install these updates of driver on Windows Update that I needed. I installed them, restarted my computer and loaded to the top of my game, after 30 minutes of play the game my laptop screen to go blank for 30 seconds then stops all the machine, qnd then refused to turn it on for two hours, initially I thought that it is hotter, but I left it for the rest of the dy and I turned it back on and it does the same thing again. It had been fine for months until I have them installed.

    Edition of Windows: Windows Vista Home Premium Service Pack 2

    System type: 32-bit

    Updates downloaded and installed:

    Microsoft Silverlight (KB974331)
    NVIDIA NVIDIA High Definition Audio - Audio - Corperation
    Conexant - Audio - Conexant high definition SmartAudio 221
    Atheros Communications Inc. - Atheros AR5007 802 network. 11 b / g WiFi adapt
    Office Genuine Advantage Notifications 9 94810 KB)
    nVidia - showing - NVIDIA GeForce 8200 M G

    Start a new thread in this forum for assistance: http://social.answers.microsoft.com/Forums/en-US/xphardware/threads ~ Robear Dyer (PA Bear) ~ MS MVP (that is to say, mail, security, Windows & Update Services) since 2002 ~ WARNING: MS MVPs represent or work for Microsoft

  • My computer crashes. Find "MPSampleSubmission error (event ID: 5000)" in Event Viewer.

    Hi all..

    I found my PC always hang...

    I always need to restart the PC, and able to operate back then...

    blocking problem is interminted...

    I couldn't estimate when going to breed to hang...

    then I found that there my event log, have many error message as below show...

    Event type: error
    Event source: MPSampleSubmission
    Event category: no
    Event ID: 5000
    Date: 23/08/2011
    Time: 14:50:48
    User: n/a
    Computer: VISION-1
    Description:
    The description for event ID (5000) in Source (MPSampleSubmission) cannot be found. The local computer may not have the information necessary registry or message DLL files to display messages from a remote computer. You may be able to use the option/auxsource = flag to retrieve this description; For more information, see Help and Support. The following information is part of the event: mptelemetry, 8024402C, endsearch, search, 2.1.6805.0, mpsigdwn.dll, 2.1.6805.0, antimalware from microsoft (bcf43643-a118-4432-aede-d861fcbcfcde), ZERO, ZERO, ZERO.
    Data:
    0000: 00 70 00 74 00 65 00 m.p.t.e 6 d.
    0008: 6 00 65 00 6 c 00 65 00 l.e.m.e d.
    0010: 74 00 72 00 79 00 2 c 00 t.r.y.,.
    0018: 20 00 38 00 30 00 32 00.8.0.2.
    0020: 34 00 34 00 30 00 32 00 4.4.0.2.
    0028: 63 00 00 20 00 65 00 2 c c.,. . e.
    0030: 6F 00 64 00 73 00 65 00 n.d.s.e.
    0038: 61 00 72 00 63 00 68 00 a.r.c.h.
    0040: 2 C 00 20 00 73 00 65 00. . OS.
    0048: 61 00 72 00 63 00 68 00 a.r.c.h.
    2nd 0050: 00 20 00 32 00 00 2 c,. .2...
    2nd 00 00 36 00 38 00 1 0058:31... 6.8.
    0060: 30 00 35 00 2nd 00 30 00 0.5... 0.
    0068: 2 c 00 20 00 6 d 00 70 00. . m.p.
    0070: 73 00 69 00 67 00 64 00 s.i.g.d.
    0078:77 00 6F 00 2nd 00 64 00 w.n.... d.
    0080: 6 c 00 6 c 00 2 c 00 20 00 l.l.. .
    0088:32 00 2e 00 31 00 2nd 00 2... 1...
    0090: 36 00 38 00 30 00 35 00 6.8.0.5.
    0098: 2nd 00 30 00 2 c 00 20 00... 0,. .
    00 a 0: 6 d 00 69 00 63 00 72 00 m.i.c.r.
    00a 8: 6f 00 73 00 6f 00 66 00 o.s.o.f.
    00b 0: 74 00 20 00 61 00 6F 00 t... a.n.
    00b 8: 74 00 69 00 6 d 00 61 00 t.i.m.a.
    00C 0: l.w.a.r. 6 c 00 77 00 61 00 72 00
    00C 8: 65 00 20 00 28 00 62 00 e... (. b.
    00D 0: 63 00 66 00 34 00 33 00 c.f.4.3.
    00D 8:36 00 34 00 33 00 - 6.4.3 00 2d.
    00e0: 61 00 31 00 31 00 38 00 a.1.1.8.
    00E8: 2d 00 34 00 34 00 33 00 -.4.4.3.
    00f0: 32 00 2d 00 61 00 65 00 2.-. a.e..
    00f8: 64 00 65 00 2d 00 64 00. d.e - .d.
    0100: 38 00 36 00 31 00 66 00 8.6.1.f.
    0108: 63 00 62 00 63 00 66 00 c.b.c.f.
    (0110: 63 00 64 00 65 00 29 00 c).
    0118: 00 20 00 2 c 4th 00 49 00,. . N.I.
    0120: 4 c 00 2 c 00 20 00 4 00 L.,. . N.
    0128:49 00 4 c 00 20 00 4e 00 I.L.. N.
    0130:49 00 4 c 00 0D 00 0 to 00 IL...

    Can someone let me know what it is... ??

    is it cause my PC always locks... ??

    Please advice...

    Thank you..

    Hi sookchan,

    ·         Have you checked the problem in safe mode?

    This event is generated when the client Forefront Endpoint Protection (FEP) cannot get updates from Windows Server Update Services (WSUS) or the Internet. This problem may be caused by the WinHTTP proxy settings.

    You can see the B method among the Advanced troubleshooting methods in this article.

    You may encounter temporary connection related errors when you use Windows Update or Microsoft Update to install updates

  • Computer crashes randomly - no entry in Event Viewer

    Computer starts up fine, but crashes randomly. Sometimes, when it's just the office with AVG running, other times sound when Remote Desktop on the server MYOB or using IE or Chrome or Outlook etc.
    Checked event viewer, nothing is there that refers to a form any error. Makes me think that it is a hardware failure.
    Our building had a power outage over the weekend and when we came back on Monday all computers had been transformed and displays the 'Boot normally, etc. safe mode"because they had lost power while remaining on.
    All except a computer seemed to recover properly. I have since replaced the power supply with a spare part and ran fine without freezing for almost an hour under duress (50 to 100% most of the time) with flash player in Chrome, IE and Outlook running, Windows Media player runs a long video SD and a few other somewhat cpu intensive programs.

    I have an Asus P5Q - VM with an Intel Pentium E5200 and 2 x 1 GB DDR2 - 800 MHz.
    A Seagate 250 GB HDD and a bootable CD/DVD drive.
    I replaced the power supply and it would freeze again. Then, I replaced the motherboard and I have yet to install it correctly but it's already freezing. I ran Memtest86 and it passed.
    I'm now beginning to think, it's the RAM (will do much more repetitive memory tests) or the CPU. But the CPU seems to act right, change of voltage as it changes frequency to save energy.

    This is XP SP3, and yes I have a real Installation CD.
    I also installed Windows 7 to find it still hangs, so I eliminated the software.

  • Internet Explorer 11 crashes after windows security IE popped up

    Hi all, I have a problem that when IE security opens a window to ask perimission using Silverlight (Sliverlight.Configuration.exe) on my computer. IE11 will never block, couldn't click on 'Allow' or 'do not allow', he could not let me click anywhere on IE. How to solve this problem?

    Thank you

    Hello

    Please try again by following the steps on the article below and let me know the result.

    How to clean a corrupted installation of Silverlight

    https://support.Microsoft.com/kb/2608523?WA=wsignin1.0

    Thank you

    Legaede

  • my microsoft windows security is not enabled.

    Now, the icon remains blue. I can't run a scan. I don't get no more windows updates. When I try to run a scan I have error occurred in the Ox80070715 program. It was beautiful last night. I deleted and downloaded again, but same problem. Help, please

    If it was working fine last night, try to restart your machine Safe Mode (press F8 repeatedly as your computer starts) and perform a restore of the system recently, when you do not have this problem:

    "How to restore Windows XP to a previous state"
      <>http://support.Microsoft.com/kb/306084 >

    HTH,
    JW

  • I BOUGHT A DELL OPTIPLEX GX270S DESKTOP AND THOSE WHO OWNED THIS COMPUTER IS MICROSOFT WINDOWS XP PROFESSIONAL DISPLAY ON THE MAIN SCREEN AND ME TOLD THE NEWSPAPER ON. ME REQUEST USERNAME AND PASSWORD, CAN SOMEONE PLEASE ME SAY WHAT I HAVE TO DO? __

    Remember - this is a public forum so never post private information such as numbers of mail or telephone!

    Ideas:

    • You have problems with programs
    • Error messages
    • Recent changes to your computer
    • What you have already tried to solve the problem
    • Help me rebot my windows xp professional

    Contact Dell > telll them the serial number SN: > ask them to send you recovery disks.

    They do it for a cost of $ small.

    Do a clean install of the operating system.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    http://support.Microsoft.com/default.aspx/KB/189126

    "Microsoft's strategy concerning lost or forgotten passwords"

    Microsoft cannot help you recover the passwords of the files and Microsoft who are lost or forgotten product features.

    http://social.answers.Microsoft.com/forums/en-us/vistasecurity/thread/3eba3150-8742-4264-be9f-0daaad2282cd

    Read theBANNING of cracking of passwords information tools information provided in these forums in the thread above posted byBill fill MSFT, moderator

    See you soon.

    Mick Murphy - Microsoft partner

  • Problem setting online after a computer crash. Windows Vista

    Dell Inspiron Portable system crash needed re-install of Vista.  1. I have re-installed Vista. 2. no wireless networks were found.  3. in the attempt to solve problems, got the message that "this computer doesn't have an adapter installed & configured wireless.  4. I checked Device Manager and no network device is listed.  It is my understanding that the wireless application is part of the hardware on this computer.  so... I guess I need a wireless driver if there is such a thing.  Any help would be appreciated!

    http://support.Dell.com/support/downloads/index.aspx

    Go to the Dell Web site > drivers and downloads Section > search for your model number > look for the latest Vista drivers > download/install the.

    The computer you are using now if you have an Internet connection with the other > download / save drivers > copy them into Flash Drive > transfer / install on another computer/laptop.

    See you soon.

    Mick Murphy - Microsoft partner

  • Microsoft windows kernel power event id 41 task 63 - Random Shut Down

    Hi guys,.

    I have a file W2K8 R2 server that was working fine until a couple of weeks, as he began to reboot itself. After checking the logs I discovered 41 kernel-power (63), I also have the dump file. If anyone can help find the root cause, I will be really grateful.

    THX

    SA

    SA

    For future reference, please change your settings to 'small' system control panel or the kernel"DMP files will be much faster for you to download and for us to download

    This accident was related to the vShield Endpoint driver slim Agent (vsepflt. sys) and the pilot of the vShield Endpoint TDI (vnetflt.sys) Manager

    We cannot tell you much more of the DMP, because it is not conclusive.  Once change you into a core DMP in Control Panel please download at least 2 DMP files.

Maybe you are looking for