an Unexplained Server 2008 R2 Audit Policy Change


good day,

our server1 (for reference renamed) had unexplained policy changes (listed below) , caused server reboot.  have wsus server performing update pushes, one, thought ie is/has , patched current levels unexplained, our other servers have not been modified.  we identified it ie core os file changes.  perhaps validate concerted microsoft update.  malware/virus/root kit scans negative , veted know it, inside , out.

thanks much,

william

________________________________________________________________________

log name:      security
source:        microsoft-windows-security-auditing
date:          9/7/2012 5:00:48 pm
event id:      4907
task category: audit policy change
level:         information
keywords:      audit success
user:          n/a
computer:      server1.domain
description:
auditing settings on object changed.

subject:
 security id:  system
 account name:  server1$
 account domain:  domain
 logon id:  0x3e7

object:
 object server: security
 object type: file
 object name: c:\windows\system32\msfeedssync.exe
 handle id: 0x98c

process information:
 process id: 0x128c
 process name: c:\windows\servicing\trustedinstaller.exe

auditing settings:
 original security descriptor: 
 new security descriptor:  s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>4907</eventid>
    <version>0</version>
    <level>0</level>
    <task>13568</task>
    <opcode>0</opcode>
    <keywords>0x8020000000000000</keywords>
    <timecreated systemtime="2012-09-08t00:00:48.962064100z" />
    <eventrecordid>695288</eventrecordid>
    <correlation />
    <execution processid="844" threadid="860" />
    <channel>security</channel>
    <computer>server1.domain</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-18</data>
    <data name="subjectusername">server1$</data>
    <data name="subjectdomainname">domain</data>
    <data name="subjectlogonid">0x3e7</data>
    <data name="objectserver">security</data>
    <data name="objecttype">file</data>
    <data name="objectname">c:\windows\system32\msfeedssync.exe</data>
    <data name="handleid">0x98c</data>
    <data name="oldsd">
    </data>
    <data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
    <data name="processid">0x128c</data>
    <data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
  </eventdata>
</event>


-----------------------------------------------
log name:      security
source:        microsoft-windows-security-auditing
date:          9/7/2012 5:00:49 pm
event id:      4907
task category: audit policy change
level:         information
keywords:      audit success
user:          n/a
computer:      server1.domain
description:
auditing settings on object changed.

subject:
 security id:  system
 account name:  server1$
 account domain:  domain
 logon id:  0x3e7

object:
 object server: security
 object type: file
 object name: c:\windows\system32\mstime.dll
 handle id: 0x984

process information:
 process id: 0x128c
 process name: c:\windows\servicing\trustedinstaller.exe

auditing settings:
 original security descriptor: 
 new security descriptor:  s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>4907</eventid>
    <version>0</version>
    <level>0</level>
    <task>13568</task>
    <opcode>0</opcode>
    <keywords>0x8020000000000000</keywords>
    <timecreated systemtime="2012-09-08t00:00:49.040065100z" />
    <eventrecordid>695289</eventrecordid>
    <correlation />
    <execution processid="844" threadid="860" />
    <channel>security</channel>
    <computer>server1.domain</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-18</data>
    <data name="subjectusername">server1$</data>
    <data name="subjectdomainname">domain</data>
    <data name="subjectlogonid">0x3e7</data>
    <data name="objectserver">security</data>
    <data name="objecttype">file</data>
    <data name="objectname">c:\windows\system32\mstime.dll</data>
    <data name="handleid">0x984</data>
    <data name="oldsd">
    </data>
    <data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
    <data name="processid">0x128c</data>
    <data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
  </eventdata>
</event>

---------------------------------------------------
log name:      security
source:        microsoft-windows-security-auditing
date:          9/7/2012 5:00:49 pm
event id:      4907
task category: audit policy change
level:         information
keywords:      audit success
user:          n/a
computer:      server1.domain
description:
auditing settings on object changed.

subject:
 security id:  system
 account name:  server1$
 account domain:  domain
 logon id:  0x3e7

object:
 object server: security
 object type: file
 object name: c:\windows\system32\msfeedsbs.dll
 handle id: 0x70c

process information:
 process id: 0x128c
 process name: c:\windows\servicing\trustedinstaller.exe

auditing settings:
 original security descriptor: 
 new security descriptor:  s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>4907</eventid>
    <version>0</version>
    <level>0</level>
    <task>13568</task>
    <opcode>0</opcode>
    <keywords>0x8020000000000000</keywords>
    <timecreated systemtime="2012-09-08t00:00:49.055665300z" />
    <eventrecordid>695290</eventrecordid>
    <correlation />
    <execution processid="844" threadid="860" />
    <channel>security</channel>
    <computer>server1.domain</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-18</data>
    <data name="subjectusername">server1$</data>
    <data name="subjectdomainname">domain</data>
    <data name="subjectlogonid">0x3e7</data>
    <data name="objectserver">security</data>
    <data name="objecttype">file</data>
    <data name="objectname">c:\windows\system32\msfeedsbs.dll</data>
    <data name="handleid">0x70c</data>
    <data name="oldsd">
    </data>
    <data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
    <data name="processid">0x128c</data>
    <data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
  </eventdata>
</event>

----------------------------
log name:      security
source:        microsoft-windows-security-auditing
date:          9/7/2012 5:00:49 pm
event id:      4907
task category: audit policy change
level:         information
keywords:      audit success
user:          n/a
computer:      server1.domain
description:
auditing settings on object changed.

subject:
 security id:  system
 account name:  server1$
 account domain:  domain
 logon id:  0x3e7

object:
 object server: security
 object type: file
 object name: c:\windows\system32\url.dll
 handle id: 0x988

process information:
 process id: 0x128c
 process name: c:\windows\servicing\trustedinstaller.exe

auditing settings:
 original security descriptor: 
 new security descriptor:  s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>4907</eventid>
    <version>0</version>
    <level>0</level>
    <task>13568</task>
    <opcode>0</opcode>
    <keywords>0x8020000000000000</keywords>
    <timecreated systemtime="2012-09-08t00:00:49.102465900z" />
    <eventrecordid>695291</eventrecordid>
    <correlation />
    <execution processid="844" threadid="860" />
    <channel>security</channel>
    <computer>server1.domain</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-18</data>
    <data name="subjectusername">server1$</data>
    <data name="subjectdomainname">domain</data>
    <data name="subjectlogonid">0x3e7</data>
    <data name="objectserver">security</data>
    <data name="objecttype">file</data>
    <data name="objectname">c:\windows\system32\url.dll</data>
    <data name="handleid">0x988</data>
    <data name="oldsd">
    </data>
    <data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
    <data name="processid">0x128c</data>
    <data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
  </eventdata>
</event>

________________________________________________________________________

log name:      security
source:        microsoft-windows-security-auditing
date:          9/7/2012 5:00:49 pm
event id:      4907
task category: audit policy change
level:         information
keywords:      audit success
user:          n/a
computer:      server1.domain
description:
auditing settings on object changed.

subject:
 security id:  system
 account name:  server1$
 account domain:  domain
 logon id:  0x3e7

object:
 object server: security
 object type: file
 object name: c:\windows\system32\mshtmled.dll
 handle id: 0x98c

process information:
 process id: 0x128c
 process name: c:\windows\servicing\trustedinstaller.exe

auditing settings:
 original security descriptor: 
 new security descriptor:  s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <system>
    <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <eventid>4907</eventid>
    <version>0</version>
    <level>0</level>
    <task>13568</task>
    <opcode>0</opcode>
    <keywords>0x8020000000000000</keywords>
    <timecreated systemtime="2012-09-08t00:00:49.118066100z" />
    <eventrecordid>695292</eventrecordid>
    <correlation />
    <execution processid="844" threadid="860" />
    <channel>security</channel>
    <computer>server1.domain</computer>
    <security />
  </system>
  <eventdata>
    <data name="subjectusersid">s-1-5-18</data>
    <data name="subjectusername">server1$</data>
    <data name="subjectdomainname">domain</data>
    <data name="subjectlogonid">0x3e7</data>
    <data name="objectserver">security</data>
    <data name="objecttype">file</data>
    <data name="objectname">c:\windows\system32\mshtmled.dll</data>
    <data name="handleid">0x98c</data>
    <data name="oldsd">
    </data>
    <data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
    <data name="processid">0x128c</data>
    <data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
  </eventdata>
</event>

_____________________________________________________

 


wh

hi,

> process c:\windows\system32\svchost.exe (server1) has initiated restart of computer server1
> on behalf of user nt authority\system
following reason: operating system: recovery (planned)

this log indicates server restart planed updates.

how configured windows updates these servers?  through domain group policies or configured on each server manually?

please run “rsop.msc” on server, check windows update group policy settings:

computer configuration --> administrative templates --> windows components --> windows update --> no auto-restart scheduled automatic update installation options

this policy specifies complete scheduled installation, automatic updates wait computer restarted user logged on, instead of causing computer restart automatically.

if status set enabled, automatic updates not restart computer automatically during scheduled installation if user logged on computer. instead, automatic updates notify user restart computer in order complete installation.

if status set disabled or not configured, automatic updates notify user computer automatically restart in 5 minutes complete installation. should enable policy disable auto restart.

also, may check below registry entry make sure whether policy enabled:

hkey_local_machine \software\policies \microsoft\windows \windowsupdate\au

0 = false (allow auto-reboot)

1 = true (disallow auto-reboot)

for more information please refer following ms articles:

configure automatic updates using group policy
http://technet.microsoft.com/en-us/library/cc720539(v=ws.10).aspx
configure automatic updates in non–active directory environment
http://technet.microsoft.com/en-us/library/cc708449(v=ws.10)
disable system auto restart after installing windows updates
http://support.microsoft.com/kb/555444

hope helps!

technet subscriber support

if technet subscription user , have feedback on our support quality, please send feedback here.


lawrence

technet community support



Windows Server  >  Group Policy



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group