Event 5447.  Don't know how to resolve all these events.
A Windows Filtering Platform filter has been changed. Subject: Security ID: S-1-5-19 Account Name: NT AUTHORITY\LOCAL SERVICE Process Information: Process ID: 536 Provider Information: ID: {DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62} Name: Windows Firewall Change Information: Change Type: %%16385 Filter Information: ID: {E41D6206-4065-4331-B705-D81C0821C0EA} Name: HP Networked Printer Installer Type: %%16388 Run-Time ID: 67493 Layer Information: ID: {88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E} Name: ALE Listen v4 Layer Run-Time ID: 40 Callout Information: ID: {00000000-0000-0000-0000-000000000000} Name: - Additional Information: Weight: 4611686018427387920 Conditions: Condition ID: {d78e1e87-8644-4ea5-9437-d809ecefc971} Match value: Equal to Condition value: 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \.d.e.v.i.c.e.\. 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k. 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 31 00 5c 00 v.o.l.u.m.e.1.\. 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\. 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2. 00000050 5c 00 73 00 70 00 6f 00-6f 00 6c 00 73 00 76 00 \.s.p.o.o.l.s.v. 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e... Filter Action: %%16390 Log Name: <Security> Source: <Microsoft-Windows-Security-Auditing> Record Number: <1846757> User: <N/A> MS Event ID: <5447> MS Event Category: <13573> (13573) MS Event Type: <8> (Security audit success) MS Insertion Strings: <['536', 'S-1-5-19', 'NT AUTHORITY\\LOCAL SERVICE', '{DECC16CA-3F33-4346-BE1E-8FB4AE0F3D62}', 'Windows Firewall', '%%16385', '{E41D6206-4065-4331-B705-D81C0821C0EA}', 'HP Networked Printer Installer', '%%16388', '67493', '{88BB5DAD-76D7-4227-9C71-DF0A3ED7BE7E}', 'ALE Listen v4 Layer', '40', '4611686018427387920', ' \tCondition ID:\t{d78e1e87-8644-4ea5-9437-d809ecefc971} \tMatch value:\tEqual to \tCondition value:\t 00000000 5c 00 64 00 65 00 76 00-69 00 63 00 65 00 5c 00 \\.d.e.v.i.c.e.\\. 00000010 68 00 61 00 72 00 64 00-64 00 69 00 73 00 6b 00 h.a.r.d.d.i.s.k. 00000020 76 00 6f 00 6c 00 75 00-6d 00 65 00 31 00 5c 00 v.o.l.u.m.e.1.\\. 00000030 77 00 69 00 6e 00 64 00-6f 00 77 00 73 00 5c 00 w.i.n.d.o.w.s.\\. 00000040 73 00 79 00 73 00 74 00-65 00 6d 00 33 00 32 00 s.y.s.t.e.m.3.2. 00000050 5c 00 73 00 70 00 6f 00-6f 00 6c 00 73 00 76 00 \\.s.p.o.o.l.s.v. 00000060 2e 00 65 00 78 00 65 00-00 00 ..e.x.e... ', '%%16390', '{00000000-0000-0000-0000-000000000000}', '-']>
June 13th, 2011 6:52pm

May need to turn off the auditing. http://technet.microsoft.com/en-us/library/dd772640(WS.10).aspx http://support.microsoft.com/kb/947226 Regards, Dave Patrick .... Microsoft Certified Professional Microsoft MVP [Windows]
Free Windows Admin Tool Kit Click here and download it now
June 13th, 2011 7:05pm

May need to turn off the auditing. http://technet.microsoft.com/en-us/library/dd772640(WS.10).aspx http://support.microsoft.com/kb/947226 Regards, Dave Patrick .... Microsoft Certified Professional Microsoft MVP [Windows]
June 13th, 2011 7:06pm

I wish I could turn it off in off from our GP. Base on our PCI rules require us to follow the CIS to aduit "Success/Failures" on this one.
Free Windows Admin Tool Kit Click here and download it now
June 13th, 2011 7:20pm

Are these Events considered a "Red Flag" or a threat? I see that this event shows a 'Windows Firewall' change.
June 14th, 2011 12:27pm

Hi wchew, Thanks for posting here. Have you recently modified any setting on this hosts? Maybe like software/hotfix installation..etc. ? These audit records indicate that the windows firewall policy “Core Networking - Router Advertisement (ICMPv6-Out)” has been just changed , but we can’t determent the root cause without further information yet. Thanks. Tiger Li Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
June 15th, 2011 1:40am

Hi wchew, If there is any update on this issue, please feel free to let us know. We are looking forward to your reply Tiger Li TechNet Subscriber Support in forum If you have any feedback on our support, please contact tngfb@microsoft.comPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
June 16th, 2011 7:58am

No, we haven't modified the host other than regular windows updates. This is a workstation with applications like Office, IM, HP printer app, and a syslog agent from Trustwave. Most of the users work is just using the web application and office. The OS is Vista Enterprise and similar problems with Win7 Pro. This is on a Group Policy, so may be one of the reasons why Vista and Win7 are both having problems. We haven't had any updates to the network/Switches/Router either.
Free Windows Admin Tool Kit Click here and download it now
June 16th, 2011 1:50pm

Hi wchew, If there is any update on this issue, please feel free to let us know. Tiger Li TechNet Subscriber Support in forum If you have any feedback on our support, please contact tngfb@microsoft.comPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
June 19th, 2011 9:53pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics