Microsoft Security Client Oobe Crash
Feb 01, 2013 2. Rebooted, message Session 'Microsoft Security Client OOBE' stopped due to the following error: 0xC000000D was still in Event Viewer. Plus there was the message that when I shut down the following occurred: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now.
Wake up from first sleep, the following four errors appear consistently. Error ID 3, The Windows Security Center Service was unable to establish event queries with WMI to monitor third party AntiVirus, AntiSpyware and Firewall. Error ID 16 (3 instances) Error while updating Windows Defender status to SECURITY_PRODUCT_STATE_ON. Wake ups thereafter do not generate those errors, which were never seen prior to 1803 HOME. Clues to banish them? Windows Defender is the sole virus app; there has never been another. Malwarebyes/ADW are installed but run on demand only. I forgot to take my prenatal vitamin.
Live monitoring is disabled. Windows 10 workstation Security log filling with Event ID 4703 My Windows 10 workstation's Security Event Log is filled with informational Event ID 4703 (like 20/second). It's an Audit Success on Authorization Policy Change category.
Pretty much all are about the javaw.exe process & SeSecurityPrivilege. But also a few of them list svchost.exe as the process & a whole list of privileges. I can't find anything on the Net about event 4703.
Sometimes it lists the privilege as Disabled (as below), and some are Enabled. Back & forth, multiple events per second. Does anyone have any idea what/why this is, or anyone else experiencing it? Here are the details of the event (edited for privacy). Task Category: Authorization Policy Change Level: Information Keywords: Audit Success User: N/A Computer: xxxxx.yyyy.com Description: A user right was adjusted. Subject: Security ID: SYSTEM Account Name: XXXXXX Account Domain: YYYYYYYY Logon ID: 0x3E7 Target Account: Security ID: SYSTEM Account Name: XXXXXXX Account Domain: YYYYYYYYY Logon ID: 0x3E7 Process Information: Process ID: 0xb24 Process Name: C: Windows SysWOW64 ContegoSPOP jre1.7.0_65 bin javaw.exe Enabled Privileges: - Disabled Privileges: SeSecurityPrivilege.