Windows XP Community - XPHeads



Event log fills up with Failure Audit events (XP-Pro)

microsoft.public.windowsxp.security_admin


Reply
  #1 (permalink)  
Old 03-22-2008, 07:32 AM
Bo Berglund
 
Posts: n/a
Event log fills up with Failure Audit events (XP-Pro)
My Event log continuously fills up with failure audit events of this
type:

The Windows Firewall has detected an application listening for
incoming traffic.

Name: -
Path: C:\WINDOWS\system32\lsass.exe
Process identifier: 1312
User account: SYSTEM
User domain: NT AUTHORITY
Service: Yes
RPC server: No
IP version: IPv4
IP protocol: UDP
Port number: 3562
Allowed: No
User notified: No

The strange thing is that I am behind a firewall so Windows Firewall
is set to OFF....
How can Windows Firewall log events if it is OFF?????

And how can I get rid of this nuisance?
I am running a fully up to date Symantec Corporate antivirus on this
PC.


Bo Berglund
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 03-22-2008, 01:06 PM
Shenan Stanley
 
Posts: n/a
Re: Event log fills up with Failure Audit events (XP-Pro)
Bo Berglund wrote:
> My Event log continuously fills up with failure audit events of this
> type:
>
> The Windows Firewall has detected an application listening for
> incoming traffic.
>
> Name: -
> Path: C:\WINDOWS\system32\lsass.exe
> Process identifier: 1312
> User account: SYSTEM
> User domain: NT AUTHORITY
> Service: Yes
> RPC server: No
> IP version: IPv4
> IP protocol: UDP
> Port number: 3562
> Allowed: No
> User notified: No
>
> The strange thing is that I am behind a firewall so Windows Firewall
> is set to OFF....
> How can Windows Firewall log events if it is OFF?????
>
> And how can I get rid of this nuisance?
> I am running a fully up to date Symantec Corporate antivirus on this
> PC.


http://www.eventid.net/display.asp?e...ri ty&phase=1

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 03-25-2008, 06:02 PM
Bo Berglund
 
Posts: n/a
Re: Event log fills up with Failure Audit events (XP-Pro)
On Sat, 22 Mar 2008 08:06:01 -0500, "Shenan Stanley"
<newshelper@gmail.com> wrote:

>Bo Berglund wrote:
>> My Event log continuously fills up with failure audit events of this
>> type:
>>
>> The Windows Firewall has detected an application listening for
>> incoming traffic.
>>
>> Name: -
>> Path: C:\WINDOWS\system32\lsass.exe
>> Process identifier: 1312
>> User account: SYSTEM
>> User domain: NT AUTHORITY
>> Service: Yes
>> RPC server: No
>> IP version: IPv4
>> IP protocol: UDP
>> Port number: 3562
>> Allowed: No
>> User notified: No
>>
>> The strange thing is that I am behind a firewall so Windows Firewall
>> is set to OFF....
>> How can Windows Firewall log events if it is OFF?????
>>
>> And how can I get rid of this nuisance?
>> I am running a fully up to date Symantec Corporate antivirus on this
>> PC.

>
>http://www.eventid.net/display.asp?e...ri ty&phase=1
>


I noticed that even if Windows Firewall is ste to off it seems to be
active anyway. So I stopped the service and set it for manual start.
Now I don't get nearly as many log entries, but I still have a fair
amount of unuseful entries, like:

A new process has been created:
New Process ID: 4908
Image File Name:
C:\Engineering\Projects\Bosse\MailCheck\MailCheck. exe
Creator Process ID: 240
User Name: Bosse
Domain: MYDOMAIN
Logon ID: (0x0,0x1ACAD)


And then after the program exits:

A process has exited:
Process ID: 4908
Image File Name:
C:\Engineering\Projects\Bosse\MailCheck\MailCheck. exe
User Name: Bosse
Domain: MYDOMAIN
Logon ID: (0x0,0x1ACAD)

What is the purpose of logging these items?
Again the event log fills up with non-usable entries.
It would have been useful if failures were logged, but why log normal
activity?

And how can I reduce this?



Bo Berglund
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 12:20 PM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74