Cancel Or allow - CMD audit success

Discussion in 'Windows - Virus and spyware problems' started by 0din, Sep 16, 2008.

  1. 0din

    0din Member

    Joined:
    Jul 6, 2007
    Messages:
    6
    Likes Received:
    0
    Trophy Points:
    11
    Hello,
    I recently bought a new PC with vista home premium

    I am a pretty techy guy
    I mainly game and (torrent)
    I was watching Cowboy Bebop and
    the security thing came up asking if CMD.exe could run
    I said no for obvious reasons
    I was suspicious that something was wrong so I went to the event viewer to check stuff out to see what happened

    This is what I got when it happened:
    (
    Log Name: Security
    Source: Microsoft-Windows-Security-Auditing
    Date: 9/16/2008 6:35:00 PM
    Event ID: 4672
    Task Category: Special Logon
    Level: Information
    Keywords: Audit Success
    User: N/A
    Computer: odin-pc
    Description:
    Special privileges assigned to new logon.

    Subject:
    Security ID: SYSTEM
    Account Name: SYSTEM
    Account Domain: NT AUTHORITY
    Logon ID: 0x3e7

    Privileges: SeAssignPrimaryTokenPrivilege
    SeTcbPrivilege
    SeSecurityPrivilege
    SeTakeOwnershipPrivilege
    SeLoadDriverPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeDebugPrivilege
    SeAuditPrivilege
    SeSystemEnvironmentPrivilege
    SeImpersonatePrivilege
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
    <EventID>4672</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>12548</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8020000000000000</Keywords>
    <TimeCreated SystemTime="2008-09-17T01:35:00.994Z" />
    <EventRecordID>2087</EventRecordID>
    <Correlation />
    <Execution ProcessID="612" ThreadID="1408" />
    <Channel>Security</Channel>
    <Computer>odin-pc</Computer>
    <Security />
    </System>
    <EventData>
    <Data Name="SubjectUserSid">S-1-5-18</Data>
    <Data Name="SubjectUserName">SYSTEM</Data>
    <Data Name="SubjectDomainName">NT AUTHORITY</Data>
    <Data Name="SubjectLogonId">0x3e7</Data>
    <Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege
    SeTcbPrivilege
    SeSecurityPrivilege
    SeTakeOwnershipPrivilege
    SeLoadDriverPrivilege
    SeBackupPrivilege
    SeRestorePrivilege
    SeDebugPrivilege
    SeAuditPrivilege
    SeSystemEnvironmentPrivilege
    SeImpersonatePrivilege</Data>
    </EventData>
    </Event>
    )

    It said something about Audit success WTF does that mean?
    Is something wrong? Was I successfully exploited from the outside X_x
    I'm not a noob I'm just new to Vista any help would be appreciated
     
  2. 2oldGeek

    2oldGeek Active member

    Joined:
    Jun 16, 2005
    Messages:
    3,658
    Likes Received:
    38
    Trophy Points:
    78
    Windows NT comes with two "command line shells" -- one called CMD.EXE and the other called COMMAND.COM

    They are Legitimate System files….

    What you are experiencing is the great Vista security crap! A program wanted to use the cmd.exe command for whatever and Vista felt it necessary to ask your permission.

    Get use to it….. it will be a little while longer before M$ comes out with a new OS that will be better than Vista but I hear it’s in the works. [​IMG]


    [​IMG]


    2OG
     

Share This Page