an Unexplained Server 2008 R2 Audit Policy Change
good day,
our server1 (for reference renamed) had unexplained policy changes (listed below) , caused server reboot. have wsus server performing update pushes, one, thought ie is/has , patched current levels unexplained, our other servers have not been modified. we identified it ie core os file changes. perhaps validate concerted microsoft update. malware/virus/root kit scans negative , veted know it, inside , out.
thanks much,
william
________________________________________________________________________
log name: security
source: microsoft-windows-security-auditing
date: 9/7/2012 5:00:48 pm
event id: 4907
task category: audit policy change
level: information
keywords: audit success
user: n/a
computer: server1.domain
description:
auditing settings on object changed.
subject:
security id: system
account name: server1$
account domain: domain
logon id: 0x3e7
object:
object server: security
object type: file
object name: c:\windows\system32\msfeedssync.exe
handle id: 0x98c
process information:
process id: 0x128c
process name: c:\windows\servicing\trustedinstaller.exe
auditing settings:
original security descriptor:
new security descriptor: s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<eventid>4907</eventid>
<version>0</version>
<level>0</level>
<task>13568</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2012-09-08t00:00:48.962064100z" />
<eventrecordid>695288</eventrecordid>
<correlation />
<execution processid="844" threadid="860" />
<channel>security</channel>
<computer>server1.domain</computer>
<security />
</system>
<eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domain</data>
<data name="subjectlogonid">0x3e7</data>
<data name="objectserver">security</data>
<data name="objecttype">file</data>
<data name="objectname">c:\windows\system32\msfeedssync.exe</data>
<data name="handleid">0x98c</data>
<data name="oldsd">
</data>
<data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
<data name="processid">0x128c</data>
<data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
</eventdata>
</event>
-----------------------------------------------
log name: security
source: microsoft-windows-security-auditing
date: 9/7/2012 5:00:49 pm
event id: 4907
task category: audit policy change
level: information
keywords: audit success
user: n/a
computer: server1.domain
description:
auditing settings on object changed.
subject:
security id: system
account name: server1$
account domain: domain
logon id: 0x3e7
object:
object server: security
object type: file
object name: c:\windows\system32\mstime.dll
handle id: 0x984
process information:
process id: 0x128c
process name: c:\windows\servicing\trustedinstaller.exe
auditing settings:
original security descriptor:
new security descriptor: s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<eventid>4907</eventid>
<version>0</version>
<level>0</level>
<task>13568</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2012-09-08t00:00:49.040065100z" />
<eventrecordid>695289</eventrecordid>
<correlation />
<execution processid="844" threadid="860" />
<channel>security</channel>
<computer>server1.domain</computer>
<security />
</system>
<eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domain</data>
<data name="subjectlogonid">0x3e7</data>
<data name="objectserver">security</data>
<data name="objecttype">file</data>
<data name="objectname">c:\windows\system32\mstime.dll</data>
<data name="handleid">0x984</data>
<data name="oldsd">
</data>
<data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
<data name="processid">0x128c</data>
<data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
</eventdata>
</event>
---------------------------------------------------
log name: security
source: microsoft-windows-security-auditing
date: 9/7/2012 5:00:49 pm
event id: 4907
task category: audit policy change
level: information
keywords: audit success
user: n/a
computer: server1.domain
description:
auditing settings on object changed.
subject:
security id: system
account name: server1$
account domain: domain
logon id: 0x3e7
object:
object server: security
object type: file
object name: c:\windows\system32\msfeedsbs.dll
handle id: 0x70c
process information:
process id: 0x128c
process name: c:\windows\servicing\trustedinstaller.exe
auditing settings:
original security descriptor:
new security descriptor: s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<eventid>4907</eventid>
<version>0</version>
<level>0</level>
<task>13568</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2012-09-08t00:00:49.055665300z" />
<eventrecordid>695290</eventrecordid>
<correlation />
<execution processid="844" threadid="860" />
<channel>security</channel>
<computer>server1.domain</computer>
<security />
</system>
<eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domain</data>
<data name="subjectlogonid">0x3e7</data>
<data name="objectserver">security</data>
<data name="objecttype">file</data>
<data name="objectname">c:\windows\system32\msfeedsbs.dll</data>
<data name="handleid">0x70c</data>
<data name="oldsd">
</data>
<data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
<data name="processid">0x128c</data>
<data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
</eventdata>
</event>
----------------------------
log name: security
source: microsoft-windows-security-auditing
date: 9/7/2012 5:00:49 pm
event id: 4907
task category: audit policy change
level: information
keywords: audit success
user: n/a
computer: server1.domain
description:
auditing settings on object changed.
subject:
security id: system
account name: server1$
account domain: domain
logon id: 0x3e7
object:
object server: security
object type: file
object name: c:\windows\system32\url.dll
handle id: 0x988
process information:
process id: 0x128c
process name: c:\windows\servicing\trustedinstaller.exe
auditing settings:
original security descriptor:
new security descriptor: s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<eventid>4907</eventid>
<version>0</version>
<level>0</level>
<task>13568</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2012-09-08t00:00:49.102465900z" />
<eventrecordid>695291</eventrecordid>
<correlation />
<execution processid="844" threadid="860" />
<channel>security</channel>
<computer>server1.domain</computer>
<security />
</system>
<eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domain</data>
<data name="subjectlogonid">0x3e7</data>
<data name="objectserver">security</data>
<data name="objecttype">file</data>
<data name="objectname">c:\windows\system32\url.dll</data>
<data name="handleid">0x988</data>
<data name="oldsd">
</data>
<data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
<data name="processid">0x128c</data>
<data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
</eventdata>
</event>
________________________________________________________________________
log name: security
source: microsoft-windows-security-auditing
date: 9/7/2012 5:00:49 pm
event id: 4907
task category: audit policy change
level: information
keywords: audit success
user: n/a
computer: server1.domain
description:
auditing settings on object changed.
subject:
security id: system
account name: server1$
account domain: domain
logon id: 0x3e7
object:
object server: security
object type: file
object name: c:\windows\system32\mshtmled.dll
handle id: 0x98c
process information:
process id: 0x128c
process name: c:\windows\servicing\trustedinstaller.exe
auditing settings:
original security descriptor:
new security descriptor: s:arai(au;safa;dclcrpcrsdwdwo;;;wd)
event xml:
<event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<system>
<provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<eventid>4907</eventid>
<version>0</version>
<level>0</level>
<task>13568</task>
<opcode>0</opcode>
<keywords>0x8020000000000000</keywords>
<timecreated systemtime="2012-09-08t00:00:49.118066100z" />
<eventrecordid>695292</eventrecordid>
<correlation />
<execution processid="844" threadid="860" />
<channel>security</channel>
<computer>server1.domain</computer>
<security />
</system>
<eventdata>
<data name="subjectusersid">s-1-5-18</data>
<data name="subjectusername">server1$</data>
<data name="subjectdomainname">domain</data>
<data name="subjectlogonid">0x3e7</data>
<data name="objectserver">security</data>
<data name="objecttype">file</data>
<data name="objectname">c:\windows\system32\mshtmled.dll</data>
<data name="handleid">0x98c</data>
<data name="oldsd">
</data>
<data name="newsd">s:arai(au;safa;dclcrpcrsdwdwo;;;wd)</data>
<data name="processid">0x128c</data>
<data name="processname">c:\windows\servicing\trustedinstaller.exe</data>
</eventdata>
</event>
_____________________________________________________
wh
hi,
> process c:\windows\system32\svchost.exe (server1) has initiated restart of computer server1
> on behalf of user nt authority\system following reason: operating system: recovery (planned)
this log indicates server restart planed updates.
how configured windows updates these servers? through domain group policies or configured on each server manually?
please run “rsop.msc” on server, check windows update group policy settings:
computer configuration --> administrative templates --> windows components --> windows update --> no auto-restart scheduled automatic update installation options
this policy specifies complete scheduled installation, automatic updates wait computer restarted user logged on, instead of causing computer restart automatically.
if status set enabled, automatic updates not restart computer automatically during scheduled installation if user logged on computer. instead, automatic updates notify user restart computer in order complete installation.
if status set disabled or not configured, automatic updates notify user computer automatically restart in 5 minutes complete installation. should enable policy disable auto restart.
also, may check below registry entry make sure whether policy enabled:
hkey_local_machine \software\policies \microsoft\windows \windowsupdate\au
0 = false (allow auto-reboot)
1 = true (disallow auto-reboot)
for more information please refer following ms articles:
configure automatic updates using group policy
http://technet.microsoft.com/en-us/library/cc720539(v=ws.10).aspx
configure automatic updates in non–active directory environment
http://technet.microsoft.com/en-us/library/cc708449(v=ws.10)
disable system auto restart after installing windows updates
http://support.microsoft.com/kb/555444
hope helps!
if technet subscription user , have feedback on our support quality, please send feedback here.
lawrence
technet community support
Windows Server > Group Policy
Comments
Post a Comment