Jump to content

Win 10 VM tons of Logon and Logoff events (4624 & 4634)

Noah0302

Hi guys,

 

I have a quick qestion weather it is normal that my Win 10 VM hat so many Logon and Logoff events.

There are over 3000 in just under a week, that seems a bit much to me

image.thumb.png.c2d24e5a28c556dba283b3a21dd5f0f9.png

 

Those 3 being the main ones:

 
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
  <EventID>4634</EventID>
  <Version>0</Version>
  <Level>0</Level>
  <Task>12545</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8020000000000000</Keywords>
  <TimeCreated SystemTime="2022-10-12T01:25:03.0142588Z" />
  <EventRecordID>1062516</EventRecordID>
  <Correlation />
  <Execution ProcessID="740" ThreadID="4800" />
  <Channel>Security</Channel>
  <Computer>Win10-PVE</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="TargetUserSid">S-1-5-90-0-2</Data>
  <Data Name="TargetUserName">DWM-2</Data>
  <Data Name="TargetDomainName">Window Manager</Data>
  <Data Name="TargetLogonId">0xaa91f</Data>
  <Data Name="LogonType">2</Data>
  </EventData>
  </Event>
 
 
 
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
  <EventID>4624</EventID>
  <Version>2</Version>
  <Level>0</Level>
  <Task>12544</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8020000000000000</Keywords>
  <TimeCreated SystemTime="2022-10-12T01:25:36.0144751Z" />
  <EventRecordID>1062910</EventRecordID>
  <Correlation ActivityID="{853ca98e-ddd9-0001-0faa-3c85d9ddd801}" />
  <Execution ProcessID="732" ThreadID="828" />
  <Channel>Security</Channel>
  <Computer>Win10-PVE</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="SubjectUserSid">S-1-5-18</Data>
  <Data Name="SubjectUserName">WIN10-PVE$</Data>
  <Data Name="SubjectDomainName">WORKGROUP</Data>
  <Data Name="SubjectLogonId">0x3e7</Data>
  <Data Name="TargetUserSid">S-1-5-96-0-1</Data>
  <Data Name="TargetUserName">UMFD-1</Data>
  <Data Name="TargetDomainName">Font Driver Host</Data>
  <Data Name="TargetLogonId">0x879b</Data>
  <Data Name="LogonType">2</Data>
  <Data Name="LogonProcessName">Advapi</Data>
  <Data Name="AuthenticationPackageName">Negotiate</Data>
  <Data Name="WorkstationName">-</Data>
  <Data Name="LogonGuid">{00000000-0000-0000-0000-000000000000}</Data>
  <Data Name="TransmittedServices">-</Data>
  <Data Name="LmPackageName">-</Data>
  <Data Name="KeyLength">0</Data>
  <Data Name="ProcessId">0x2a8</Data>
  <Data Name="ProcessName">C:\Windows\System32\winlogon.exe</Data>
  <Data Name="IpAddress">-</Data>
  <Data Name="IpPort">-</Data>
  <Data Name="ImpersonationLevel">%%1833</Data>
  <Data Name="RestrictedAdminMode">-</Data>
  <Data Name="TargetOutboundUserName">-</Data>
  <Data Name="TargetOutboundDomainName">-</Data>
  <Data Name="VirtualAccount">%%1842</Data>
  <Data Name="TargetLinkedLogonId">0x0</Data>
  <Data Name="ElevatedToken">%%1843</Data>
  </EventData>
  </Event>
 
 
 
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
  <EventID>4624</EventID>
  <Version>2</Version>
  <Level>0</Level>
  <Task>12544</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8020000000000000</Keywords>
  <TimeCreated SystemTime="2022-10-12T01:25:36.0151918Z" />
  <EventRecordID>1062911</EventRecordID>
  <Correlation ActivityID="{853ca98e-ddd9-0001-0faa-3c85d9ddd801}" />
  <Execution ProcessID="732" ThreadID="784" />
  <Channel>Security</Channel>
  <Computer>Win10-PVE</Computer>
  <Security />
  </System>
- <EventData>
  <Data Name="SubjectUserSid">S-1-5-18</Data>
  <Data Name="SubjectUserName">WIN10-PVE$</Data>
  <Data Name="SubjectDomainName">WORKGROUP</Data>
  <Data Name="SubjectLogonId">0x3e7</Data>
  <Data Name="TargetUserSid">S-1-5-18</Data>
  <Data Name="TargetUserName">SYSTEM</Data>
  <Data Name="TargetDomainName">NT-AUTORITÄT</Data>
  <Data Name="TargetLogonId">0x3e7</Data>
  <Data Name="LogonType">5</Data>
  <Data Name="LogonProcessName">Advapi</Data>
  <Data Name="AuthenticationPackageName">Negotiate</Data>
  <Data Name="WorkstationName">-</Data>
  <Data Name="LogonGuid">{00000000-0000-0000-0000-000000000000}</Data>
  <Data Name="TransmittedServices">-</Data>
  <Data Name="LmPackageName">-</Data>
  <Data Name="KeyLength">0</Data>
  <Data Name="ProcessId">0x2d4</Data>
  <Data Name="ProcessName">C:\Windows\System32\services.exe</Data>
  <Data Name="IpAddress">-</Data>
  <Data Name="IpPort">-</Data>
  <Data Name="ImpersonationLevel">%%1833</Data>
  <Data Name="RestrictedAdminMode">-</Data>
  <Data Name="TargetOutboundUserName">-</Data>
  <Data Name="TargetOutboundDomainName">-</Data>
  <Data Name="VirtualAccount">%%1843</Data>
  <Data Name="TargetLinkedLogonId">0x0</Data>
  <Data Name="ElevatedToken">%%1842</Data>
  </EventData>
  </Event>
 
 

 

 

Thanks in advance!

My Gaming PC:
Inno3D iChill Black - RTX 4080 - +500 Memory, undervolted Core, 2xCorsair QX120 (push) + 2xInno3D 120mm (pull)
AMD Ryzen 7 7800X3D - NZXT x72
G.SKILL Trident Z @6000MHz CL30 - 2x16GB
Asus Strix X670E-E Gaming

1x500GB Samsung 960 Pro (Windows 11)

1x2TB Kingston KC3000 (Games)

1x1TB WD Blue SN550 (Programs)

1x1TB Samsung 870 EVO (Programs)
Corsair RM-850X

Lian Li O11 Vision
ASUS ROG Swift OLED PG27AQDM (240hz OLED), MSI Optix MAG274QRFDE-QD, BenQ ZOWIE XL2720

Logitech G Pro Wireless Superlight
Wooting 60HE

Audeze LCD2-C + FiiO K3

Klipsch RP600-M + Klipsch R-120 SW

 

My Notebook:

MacBook Pro 16 M1 - 16GB

 

Proxmox-Cluster:

  • Ryzen 9 3950X, Asus Strix X570E F-Gaming, 2x32GB3200MHz ECC, 2x 512GB NVMe ZFS-Mirror (Boot + Testing-VMs), 2x14TB ZFS-Mirror + 1x3TB (TrueNAS-VM), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 10G NIC
  • i7 8700k delidded undervolted, Gigabyte Z390 UD, 4x16GB 3200MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 2,5G NIC
  • i5 4670, 3x4GB + 1x8GB 1600MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 2,5G NIC

Proxmox-Backup-Server:

  • i5 4670, 4x4GB 1600MHz, 2x2TB ZFS-Mirror, 2,5G NIC
Link to comment
Share on other sites

Link to post
Share on other sites

It's quite normal, especially if you have any tasks etc...running as those accounts. I see 2 of those accounts are interactive logons, one of which is the system (I assume that Windows Font Driver is some sort of standard windows task that runs per user) while the last is a service. If that service is frequenty triggered (stop/start) then that could be whats causing a lot of those entries. 

Spoiler

Desktop: Ryzen9 5950X | ASUS ROG Crosshair VIII Hero (Wifi) | EVGA RTX 3080Ti FTW3 | 32GB (2x16GB) Corsair Dominator Platinum RGB Pro 3600Mhz | EKWB EK-AIO 360D-RGB | EKWB EK-Vardar RGB Fans | 1TB Samsung 980 Pro, 4TB Samsung 980 Pro | Corsair 5000D Airflow | Corsair HX850 Platinum PSU | Asus ROG 42" OLED PG42UQ + LG 32" 32GK850G Monitor | Roccat Vulcan TKL Pro Keyboard | Logitech G Pro X Superlight  | MicroLab Solo 7C Speakers | Audio-Technica ATH-M50xBT2 LE Headphones | TC-Helicon GoXLR | Audio-Technica AT2035 | LTT Desk Mat | XBOX-X Controller | Windows 11 Pro

 

Spoiler

Server: Fractal Design Define R6 | Ryzen 3950x | ASRock X570 Taichi | EVGA GTX1070 FTW | 64GB (4x16GB) Corsair Vengeance LPX 3000Mhz | Corsair RM850v2 PSU | Fractal S36 Triple AIO | 12 x 8TB HGST Ultrastar He10 (WD Whitelabel) | 500GB Aorus Gen4 NVMe | 2 x 2TB Samsung 970 Evo Plus NVMe | LSI 9211-8i HBA

 

Link to comment
Share on other sites

Link to post
Share on other sites

11 hours ago, Jarsky said:

It's quite normal, especially if you have any tasks etc...running as those accounts. I see 2 of those accounts are interactive logons, one of which is the system (I assume that Windows Font Driver is some sort of standard windows task that runs per user) while the last is a service. If that service is frequenty triggered (stop/start) then that could be whats causing a lot of those entries. 

Thank you, I was getting a bit paranoid that someone has access to my VPN and VM.

My Gaming PC:
Inno3D iChill Black - RTX 4080 - +500 Memory, undervolted Core, 2xCorsair QX120 (push) + 2xInno3D 120mm (pull)
AMD Ryzen 7 7800X3D - NZXT x72
G.SKILL Trident Z @6000MHz CL30 - 2x16GB
Asus Strix X670E-E Gaming

1x500GB Samsung 960 Pro (Windows 11)

1x2TB Kingston KC3000 (Games)

1x1TB WD Blue SN550 (Programs)

1x1TB Samsung 870 EVO (Programs)
Corsair RM-850X

Lian Li O11 Vision
ASUS ROG Swift OLED PG27AQDM (240hz OLED), MSI Optix MAG274QRFDE-QD, BenQ ZOWIE XL2720

Logitech G Pro Wireless Superlight
Wooting 60HE

Audeze LCD2-C + FiiO K3

Klipsch RP600-M + Klipsch R-120 SW

 

My Notebook:

MacBook Pro 16 M1 - 16GB

 

Proxmox-Cluster:

  • Ryzen 9 3950X, Asus Strix X570E F-Gaming, 2x32GB3200MHz ECC, 2x 512GB NVMe ZFS-Mirror (Boot + Testing-VMs), 2x14TB ZFS-Mirror + 1x3TB (TrueNAS-VM), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 10G NIC
  • i7 8700k delidded undervolted, Gigabyte Z390 UD, 4x16GB 3200MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 2,5G NIC
  • i5 4670, 3x4GB + 1x8GB 1600MHz, 1x 512GB SSD (Boot), 1x 1TB Samsung 980 Pro NVMe (Ceph-OSD), 2,5G NIC

Proxmox-Backup-Server:

  • i5 4670, 4x4GB 1600MHz, 2x2TB ZFS-Mirror, 2,5G NIC
Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×