| Windows 7: Unauthorized Access??? Help interpreting Event Viewer |
01 Nov 2011
|
#1 | | |
Unauthorized Access??? Help interpreting Event Viewer Hi.
I just got home and found my computer turned on.
It had been in sleep mode for a few days..
The screen saver was on, and once I moved the mouse I had to enter the password to login.
What is driving me crazy is, something woke it up... And I don't know if someone accessed my files...
I am guessing it could be one of 3 things:
1-Someone or something moved the mouse or pressed a key.
2-Someone at my house tried to/accessed it.
3-Someone woke it by lan and accessed it remotely.
(I was/am worried about this one because I have Log Me In installed - but I checked the LMI log and it was clear).
I got home at 12:45 am. I checked the Event viewer and noticed that a login had happened at 11:50pm something.
The problem is, I did some tests and realized that just moving the mouse and waking up the computer (without entering password and access windows) causes the Event Viewer to add a "logon" event, even though access was never granted.
Could someone help me interpret these logs and tell me if the operating system was actually accessed between 11:59 and 12:40pm?
(I also have the detailed logs I could post... is it safe to share those?)
(these were mine: I got home at 12:45)
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4634 Logoff
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4648 Logon
(All of these happened while I was away)
Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4905 Audit Policy Change
Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4904 Audit Policy Change
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:02:59 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4648 Logon
Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4624 Logon
PS: I am behind a router, Security Essentials and Win Firewall ON, and windows password is very safe (14 digits). | My System Specs |
| System Manufacturer/Model Number Gateway Sx-2800 OS Win 7 x64 |
01 Nov 2011
|
#2 | | Win 8 Release candidate 8400 |

Quote: Originally Posted by gtalarico Hi.
I just got home and found my computer turned on.
It had been in sleep mode for a few days..
The screen saver was on, and once I moved the mouse I had to enter the password to login.
What is driving me crazy is, something woke it up... And I don't know if someone accessed my files...
I am guessing it could be one of 3 things:
1-Someone or something moved the mouse or pressed a key.
2-Someone at my house tried to/accessed it.
3-Someone woke it by lan and accessed it remotely.
(I was/am worried about this one because I have Log Me In installed - but I checked the LMI log and it was clear).
I got home at 12:45 am. I checked the Event viewer and noticed that a login had happened at 11:50pm something.
The problem is, I did some tests and realized that just moving the mouse and waking up the computer (without entering password and access windows) causes the Event Viewer to add a "logon" event, even though access was never granted.
Could someone help me interpret these logs and tell me if the operating system was actually accessed between 11:59 and 12:40pm?
(I also have the detailed logs I could post... is it safe to share those?)
(these were mine: I got home at 12:45)
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4634 Logoff
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:49:59 AM Microsoft Windows security auditing. 4648 Logon
(All of these happened while I was away)
Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4905 Audit Policy Change
Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4904 Audit Policy Change
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:02:59 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4624 Logon
Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4648 Logon
Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4672 Special Logon
Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4624 Logon
PS: I am behind a router, Security Essentials and Win Firewall ON, and windows password is very safe (14 digits). You cant tell from just this log but I would not worry about it unless someone with physical access has your 14 digit password. It would take them years to break it. | My System Specs | | System Manufacturer/Model Number HP Pavillion dv-7 1005 Tx OS Win 8 Release candidate 8400 CPU 2@2.4 Memory 4 gigs Graphics Card Nvidia 9600M Sound Card HD built-in Monitor(s) Displays 17" Wxga Screen Resolution 1440x900 Cooling none Internet Speed 45Mb down 5Mb up |
01 Nov 2011
|
#3 | | Windows 7 x64 Ultimate A Finnish immigrant in Leipzig, Germany |

Quote: Originally Posted by gtalarico ...
...
(All of these happened while I was away) - Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 11/1/2011 12:10:00 AM Microsoft Windows security auditing. 4624 Logon
- Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4905 Audit Policy Change
- Audit Success 11/1/2011 12:04:33 AM Microsoft Windows security auditing. 4904 Audit Policy Change
- Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
- Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 11/1/2011 12:04:08 AM Microsoft Windows security auditing. 4624 Logon
- Audit Success 11/1/2011 12:02:59 AM Microsoft Windows security auditing. 4616 Security State Change
- Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 11/1/2011 12:01:27 AM Microsoft Windows security auditing. 4624 Logon
- Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
- Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
- Audit Success 11/1/2011 12:00:13 AM Microsoft Windows security auditing. 4616 Security State Change
- Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4624 Logon
- Audit Success 11/1/2011 12:00:00 AM Microsoft Windows security auditing. 4648 Logon
- Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4672 Special Logon
- Audit Success 10/31/2011 11:59:54 PM Microsoft Windows security auditing. 4624 Logon
Reading from bottom (19) to top (1), this is what seems to have happened: - 19. to 15.: Windows Task Scheduler logs in using administrative rights.
- 14. to 9.: Windows has synced the time, I'm not sure why it took four attempts.
- 8. to 1.: Windows has added an event source to log (ID 4904) and removed it (ID 4905). Happens for instance when Task Scheduler kicks in to do a task which is then not needed / not done.
I would not worry, looks normal Windows background maintenance.
Kari | My System Specs | | Computer type Laptop System Manufacturer/Model Number HP ENVY 17-1150eg OS Windows 7 x64 Ultimate CPU 1.6 GHz Intel Core i7-720QM Processor Memory 6 GB Graphics Card ATI Mobility Radeon HD 5850 Graphics Sound Card Beats sound system with integrated subwoofer Monitor(s) Displays 17" laptop display, 22" LCD and 32" Full HD TV through HDMI Screen Resolution 1600*900, 1680*1050 and 1920*1080 Keyboard Logitech diNovo Media Desktop Laser (bluetooth) Mouse Logitech MX1000 Laser (Bluetooth) Hard Drives Internal: 2 x 500 GB SATA Hard Disk Drive 7200 rpm
External: 2TB for backups, 3TB USB3 network drive for media Internet Speed 50/10 Mbps VDSL Antivirus MSE, Windows Defender Browser Maxthon 3.5.2. Other Info Windows 7 Ultimate Retail Full in English, additional Guest-user accounts in Finnish, German and Swedish (Working languages English & Swedish, Family language German, my own language, mother tongue, Finnish. I really need Ultimate to get to use Language Packs!) |
01 Nov 2011
|
#4 | | |
Thanks for your help.
So can Task Scheduler wake the computer up from sleep?
If not, then I will just have to move on with my life, never knowing what woke my computer up...
(sneaky roommate, ghost, evil spirits, mouse ?)
At least I feel better knowing the system wasn't accessed. | My System Specs | | System Manufacturer/Model Number Gateway Sx-2800 OS Win 7 x64 |
01 Nov 2011
|
#5 | | |
Problem solved!!!
Kari, you are my hero for mentioning the Task Scheduler.
I decided to investigate that and I found an entry that my back up program created (see image)
Conclusion: The Task Scheduler CAN and WILL wake the computer up!
(I am very curious to how it actually manages to do that!!!  )
(Also noticed it started 6 seconds BEFORE the actual time... the description of one of
"policy change" events mentioned something about adjusting clock...  )
Thanks again all of you for your help! | My System Specs | | System Manufacturer/Model Number Gateway Sx-2800 OS Win 7 x64 |
02 Nov 2011
|
#6 | | Windows 7 x64 Ultimate A Finnish immigrant in Leipzig, Germany |

Quote: Originally Posted by gtalarico
(Also noticed it started 6 seconds BEFORE the actual time... the description of one of
"policy change" events mentioned something about adjusting clock...  ) Yes, the event ID 4616 means time sync.
Kari | My System Specs | | Computer type Laptop System Manufacturer/Model Number HP ENVY 17-1150eg OS Windows 7 x64 Ultimate CPU 1.6 GHz Intel Core i7-720QM Processor Memory 6 GB Graphics Card ATI Mobility Radeon HD 5850 Graphics Sound Card Beats sound system with integrated subwoofer Monitor(s) Displays 17" laptop display, 22" LCD and 32" Full HD TV through HDMI Screen Resolution 1600*900, 1680*1050 and 1920*1080 Keyboard Logitech diNovo Media Desktop Laser (bluetooth) Mouse Logitech MX1000 Laser (Bluetooth) Hard Drives Internal: 2 x 500 GB SATA Hard Disk Drive 7200 rpm
External: 2TB for backups, 3TB USB3 network drive for media Internet Speed 50/10 Mbps VDSL Antivirus MSE, Windows Defender Browser Maxthon 3.5.2. Other Info Windows 7 Ultimate Retail Full in English, additional Guest-user accounts in Finnish, German and Swedish (Working languages English & Swedish, Family language German, my own language, mother tongue, Finnish. I really need Ultimate to get to use Language Packs!) Unauthorized Access??? Help interpreting Event Viewer problems? All times are GMT -5. The time now is 01:32 AM. | |