Event ID 4797

I checked my logs and see the same error message on both my desktop and notebook. 61 events in the last hour, hundreds in the last week. They're showing up under the "Audit Success" event type. The "Target Account Name" on both machines is "HomeGroupUser$". Both machines are part of my HomeGroup. Both machines show no infections after scanning with both NOD32 & Malwarebytes.

Thats encouraging news. Perhaps this isn't uncommon or suspicious at all. Hopefully Kaspersky will say yay or nay on the issue.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
Yes it is. His avatar says he is running Windows 8 x64 Enterprise not Professional

Not sure what you mean. Enterprise or Pro shouldn't matter in this case.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
True it shouldn't I can't the view that kapersky forum posting anymore what did the say is your post still active?
Did Kapersky say Yay or Nay we won't look into this?
 
Last edited:

My Computer

System One

  • OS
    Windows 8 X64 Pro

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
I have the exact same problem.
Same event, bombing my administrator account multiple times within like 30 seconds.
I also noticed a system hang during that time but I'm not yet sure if it is related to this event in any way.
 

My Computer

System One

  • OS
    Windows 8
I have the exact same problem.
Same event, bombing my administrator account multiple times within like 30 seconds.
I also noticed a system hang during that time but I'm not yet sure if it is related to this event in any way.

I've not experienced any hangs or bahavior issues with my PC other than the suspicious event logs. Can you list what applications you have installed? I did have to uninstall Malwarebytes thought as it causes compatibility problems with Kaspersky. It wasn't detecting malware anyway.



No one has reponded to my post in Kaspesky's forum, so no news on my end. I ran scans using Eset's online scanner and also with SuperAntispyware and they come up clean as well.

Perhaps others here should start topics over at their respective AV vendor? The more eyes we have on this, the quicker we get it resolved.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
I have the exact same problem.
Same event, bombing my administrator account multiple times within like 30 seconds.
I also noticed a system hang during that time but I'm not yet sure if it is related to this event in any way.

I've not experienced any hangs or bahavior issues with my PC other than the suspicious event logs. Can you list what applications you have installed? I did have to uninstall Malwarebytes thought as it causes compatibility problems with Kaspersky. It wasn't detecting malware anyway.



No one has reponded to my post in Kaspesky's forum, so no news on my end. I ran scans using Eset's online scanner and also with SuperAntispyware and they come up clean as well.

Perhaps others here should start topics over at their respective AV vendor? The more eyes we have on this, the quicker we get it resolved.

I don't believe my system hangs are related to my events to be honest.
My system hangs started after I re formatted my computer installing windows 7, right from the start. I thought it's just some weird software issue but they happen in windows 8 as well.

I'm using windows defender atm.
 

My Computer

System One

  • OS
    Windows 8
I have the exact same problem.
Same event, bombing my administrator account multiple times within like 30 seconds.
I also noticed a system hang during that time but I'm not yet sure if it is related to this event in any way.

I've not experienced any hangs or bahavior issues with my PC other than the suspicious event logs. Can you list what applications you have installed? I did have to uninstall Malwarebytes thought as it causes compatibility problems with Kaspersky. It wasn't detecting malware anyway.



No one has reponded to my post in Kaspesky's forum, so no news on my end. I ran scans using Eset's online scanner and also with SuperAntispyware and they come up clean as well.

Perhaps others here should start topics over at their respective AV vendor? The more eyes we have on this, the quicker we get it resolved.

I don't believe my system hangs are related to my events to be honest.
My system hangs started after I re formatted my computer installing windows 7, right from the start. I thought it's just some weird software issue but they happen in windows 8 as well.

I'm using windows defender atm.

Can you list all programs you have installed?
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
I've not experienced any hangs or bahavior issues with my PC other than the suspicious event logs. Can you list what applications you have installed? I did have to uninstall Malwarebytes thought as it causes compatibility problems with Kaspersky. It wasn't detecting malware anyway.



No one has reponded to my post in Kaspesky's forum, so no news on my end. I ran scans using Eset's online scanner and also with SuperAntispyware and they come up clean as well.

Perhaps others here should start topics over at their respective AV vendor? The more eyes we have on this, the quicker we get it resolved.

I don't believe my system hangs are related to my events to be honest.
My system hangs started after I re formatted my computer installing windows 7, right from the start. I thought it's just some weird software issue but they happen in windows 8 as well.

I'm using windows defender atm.

Can you list all programs you have installed?
Uhh, what for?
 

My Computer

System One

  • OS
    Windows 8
I have those same events but I believe this is normal. It looks to me that windows is doing a security audit to see if any of your accounts have blank passwords which could be a security risk. It checks my Admin and Guest accounts which do have passwords and the event says "Audit success". I would think that if you have a blank password on an account it would raise an event to let you know.

Jim :cool:
 

My Computer

System One

  • OS
    Windows 7 HP 64bit, Windows 8.1 Pro w/Media Center 64BIT
    Computer type
    PC/Desktop
    System Manufacturer/Model
    ASUS - Home Built
    CPU
    AMD Phenom II X6 1100T
    Motherboard
    ASUS M5A99X EVO
    Memory
    Crucial Balistic DDR-3 1866 CL 9 (8 GB)
    Graphics Card(s)
    MSI R6850 Cyclone IGD5 PE
    Sound Card
    On Chip
    Monitor(s) Displays
    ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
    Screen Resolution
    1920 x 1080
    Hard Drives
    Two WD Cavier Black 2TB Sata 6gbs
    WD My Book Essential 2TB USB 3.0
    PSU
    Seasonic X650 80 Plus GOLD Modular
    Case
    Corsair 400R
    Cooling
    Antec Kuhler H2O 620, Two 120mm and four 140mm
    Keyboard
    AVS Gear Blue LED Backlight
    Mouse
    Logitech Marble Mouse USB, Logitech Precision Game Pad
    Internet Speed
    15MB
    Antivirus
    NIS, Malwarebytes Premium 2
    Other Info
    APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program,
    Motorola SB6120 Gigabit Cable Modem.
    Brother HL-2170W Laser Printer,
    Epson V300 Scanner
I don't believe my system hangs are related to my events to be honest.
My system hangs started after I re formatted my computer installing windows 7, right from the start. I thought it's just some weird software issue but they happen in windows 8 as well.

I'm using windows defender atm.

Can you list all programs you have installed?
Uhh, what for?

Just comparing what programs we might share in common to determine a pattern.




I have those same events but I believe this is normal. It looks to me that windows is doing a security audit to see if any of your accounts have blank passwords which could be a security risk. It checks my Admin and Guest accounts which do have passwords and the event says "Audit success". I would think that if you have a blank password on an account it would raise an event to let you know.

Jim :cool:

Unfortunately, that's not the case. I just enabled my guest account w/ no password, rebooted and the same event showed back up, just like always with no failed audits or warnings about vulnerable accounts of any kind.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
Windows 8 Event ID 4797 in Security Log

one guy says it's a root kit

Both Of my PC's with 4797 came back clean with the malwarebytes anti root kit utility

MBAR says system is clean. Autoruns also indicates there are no App_init DLLs.

I sent an email directly to Kaspersky Support hoping they will respond. They're about 3 days away from me re-imaging my PC.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
MBAR found nothing on my PC's either.

I'm thinking we're going to find out it's just Windows being well, you know, Windows.
:huh:
 

My Computer

System One

  • OS
    Windows 8.1 Pro x64
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Dell E520
    CPU
    Intel Q6700 Core 2 Quad - 2.66 GHz
    Motherboard
    Whatever Dell put in there...
    Memory
    8 GB Mushkin 800 MHz DDR2
    Graphics Card(s)
    NVIDIA GTX 650 - 2 GB GDDR5
    Sound Card
    Integrated
    Monitor(s) Displays
    2 x 19" ViewSonic LCD's
    Screen Resolution
    2560 x 1024
    Hard Drives
    1 Intel X25-M 120G SSD, 2 WD RE4 2TB HD's
    PSU
    PCPower & Cooling Silencer 500 Watt
    Internet Speed
    100/10 Time Warner Cable
MBAR found nothing on my PC's either.

I'm thinking we're going to find out it's just Windows being well, you know, Windows.
:huh:

I remain skeptical as well. I hope you're right.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
Yea is this a new feature that even Microsoft won't comment on in their own forums...
61 times..hundreds in weeks? My moms windows 8 home is even doing it. It's definitely solely related to windows 8 that i can see any Windows 7 users out there with 4797's??????????
I checked Dad's Windows 7 Home Premium. Not a single 4797 in it.
 

My Computer

System One

  • OS
    Windows 8 X64 Pro
Back
Top