Event ID 4797

Yea is this a new feature that even Microsoft won't comment on in their own forums...
61 times..hundreds in weeks? My moms windows 8 home is even doing it. It's definitely solely related to windows 8 that i can see any Windows 7 users out there with 4797's??????????
I checked Dad's Windows 7 Home Premium. Not a single 4797 in it.

I have a Win 7 Home Prem laptop and no 4797's either. It appears to be Win 8 specific.
 

My Computer

System One

  • OS
    Windows 10 Pro 64-bit
    Computer type
    PC/Desktop
    CPU
    AMD Athlon II X2 260 @ 3.2GHz
    Motherboard
    Asus M4A88T-EVO
    Memory
    8GB
    Graphics Card(s)
    Asus Radeon R7 240 2GB
    Sound Card
    Realtek Integrated
    PSU
    Seasonic
I have a brand new laptop (10 days old) with this issue. The laptop is running like a dog which is what prompted me to start looking through the logs in the first place. Apps are constantly being reported as "not responding". The only software I have installed so far is Mozilla Thunderbird email client and Chrome browser. I am going to have to uninstall Chrome as it is completely unusable now despite being fine for the first few days. This error started 4 days ago which is when I first noticed these performance errors. Unlikely to be a coincidence I would say. I am running Norton Internet Security.
 

My Computer

System One

  • OS
    Win 8
    System Manufacturer/Model
    Samsung NP350VC-S09AU
    CPU
    Intel i7 3630QM
    Memory
    8 GB
    Graphics Card(s)
    AMD 1 GB
What brand of laptop have you paid for that Norton security yet?

This is a Samsung NP350VC. Since yesterday's post I have realised the issue has been going on since the day I got it - must have had the logs filtered yesterday. Norton is still on the 60 day trial. Really disappointed with this laptop so far. My work laptop (Win 7) has a lower spec cpu and less RAM but runs rings around this thing.
 

My Computer

System One

  • OS
    Win 8
    System Manufacturer/Model
    Samsung NP350VC-S09AU
    CPU
    Intel i7 3630QM
    Memory
    8 GB
    Graphics Card(s)
    AMD 1 GB
What brand of laptop have you paid for that Norton security yet?

This is a Samsung NP350VC. Since yesterday's post I have realised the issue has been going on since the day I got it - must have had the logs filtered yesterday. Norton is still on the 60 day trial. Really disappointed with this laptop so far. My work laptop (Win 7) has a lower spec cpu and less RAM but runs rings around this thing.

I would uninstall everything that is not needed. and go with www.avast.com antivirus. not Symantec. Avast Is Free.
Alot of times there is Excessive software (Known As Bloatware) installed on new name brand name retail laptops/pc's that make run very slow/crawl.
 

My Computer

System One

  • OS
    Windows 8 X64 Pro
Hey guys I have been having the same problems with this stupid 4797 event. It was happening all the frikkin time. I played with some Local Policy Settings in the group policy editor and now these events only occur during logon (Which I think they are supposed to any way based on the policy).

Local Computer Policy -> Windows Settings --> Account Policies --> Password Policy --> Minimum Password Length - default "0"
(I switched this to 5, anything but 0)


Local Computer Policy -> Windows Settings --> Account Policies --> Local Policies --> Security Options -> Accounts: Limit Local Use of Blank Passwords to console logon only - Default - "Enabled"
(I switched this to disabled)

for what ever reason the security events have stopped, I only see them during logon and that is it. not every minute for days...

I hope this helps, maybe its just a buggy policy that Microsoft needs to address, I dont know
 
Last edited:

My Computer

System One

  • OS
    Windows 8 Pro
    System Manufacturer/Model
    My Build
    CPU
    AMD 8120 8 core OCd to 4.6Ghz
    Motherboard
    ASRock 970 Extreme 3
    Memory
    16 Gb DDR 3 -1600
    Graphics Card(s)
    AMD Radeon 9750 3 Gb Ocd
    Sound Card
    On-Board
    Monitor(s) Displays
    Dual 24 inch Flat panel
    Screen Resolution
    1920 * 1080
    Hard Drives
    Corsair 250 Gb SSD - Barracuda 1.5Tb Slave
    PSU
    Thermaltake Modular 850
    Case
    Cooler Master HAF Full Tower
    Cooling
    Liquid
Hey guys I have been having the same problems with this stupid 4797 event. It was happening all the frikkin time. I played with some Local Policy Settings in the group policy editor and now these events only occur during logon (Which I think they are supposed to any way based on the policy).

Local Computer Policy -> Windows Settings --> Account Policies --> Password Policy --> Minimum Password Length - default "0"
(I switched this to 5, anything but 0)


Local Computer Policy -> Windows Settings --> Account Policies --> Local Policies --> Security Options -> Accounts: Limit Local Use of Blank Passwords to console logon only - Default - "Enabled"
(I switched this to disabled)

for what ever reason the security events have stopped, I only see them during logon and that is it. not every minute for days...

I hope this helps, maybe its just a buggy policy that Microsoft needs to address, I dont know


Ok so It started happening again, though it hadn't all day after I changed the settings in the local policies. but I just watched Netflix and surfed the web. This told me it was just a coincidence. So I decided to try and hunt down what was prompting it.

With a clean desktop in the event viewer open I would do things and see if the 4797 showed up.

I found this.

Anytime i opened a new instance of the file explorer the 4797 logged. Just browsing the files system did not prompt any new 4797 logs until I closed the explorer and opened a fresh instance.

I opened up Word and as soon as it needed to access the file system either to save or retrieve a file the 4797 logged.


Why the hell does Windows 8 run this audit check when accessing the files? I'm done ****ing with it for now. Hopefully Microsoft will address this at some point. At least I can pretty much say it doesn't appear to be malicious or external. Its Windows being a dumb ass. Or there's a genius reason for it and I just don't get it..
 
Last edited:

My Computer

System One

  • OS
    Windows 8 Pro
    System Manufacturer/Model
    My Build
    CPU
    AMD 8120 8 core OCd to 4.6Ghz
    Motherboard
    ASRock 970 Extreme 3
    Memory
    16 Gb DDR 3 -1600
    Graphics Card(s)
    AMD Radeon 9750 3 Gb Ocd
    Sound Card
    On-Board
    Monitor(s) Displays
    Dual 24 inch Flat panel
    Screen Resolution
    1920 * 1080
    Hard Drives
    Corsair 250 Gb SSD - Barracuda 1.5Tb Slave
    PSU
    Thermaltake Modular 850
    Case
    Cooler Master HAF Full Tower
    Cooling
    Liquid
I have noticed that this is related to doing a refresh in Windows File Explorer.

Try this:

Load Nirsoft 'MyEventViewer' to monitor the events.

Open File Explorer.

Right click and select Refresh.

Every time I do this I immediately see two events:

1) An attempt was made to query the existence of a blank password for an account.

Subject:
Security ID: xxxxxxxxxxxxxxxxxxx
Account Name: Jim
Account Domain: Morbius
Logon ID: xxxxxxxxxxxx


Additional Information:
Caller Workstation: MORBIUS
Target Account Name: Administrator
Target Account Domain: Morbius

2) An attempt was made to query the existence of a blank password for an account.

Subject:
Security ID: xxxxxxxxxxxxxxxxxxx
Account Name: Jim
Account Domain: Morbius
Logon ID: xxxxxxxxxxxxxx


Additional Information:
Caller Workstation: MORBIUS
Target Account Name: Guest
Target Account Domain: Morbius
 

My Computer

System One

  • OS
    Windows 8.1 Pro with Media Center (64-bit)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Custom-build
    CPU
    Intel Core i7-2600K @ 4.3 GHz
    Motherboard
    ASUS P8P67 PRO Rev 3.0
    Memory
    16 GB G.SKILL Ripjaws X DDR3 SDRAM DDR3 1600 (4 banks 4GB DIMM DDR3 8-8-8-24 5-32-12-7 1T 1.5V)
    Graphics Card(s)
    NVIDIA GeForce GT 440
    Sound Card
    Firewire Focusrite Saffire Pro 14
    Monitor(s) Displays
    LG W2353V
    Screen Resolution
    1920x1080
    Hard Drives
    2 of Seagate Barracuda XT ST32000641AS (2TB ea.);
    1 of Seagate Barracuda Green ST2000DL003 (2TB);
    1 of Hitachi Deskstar HDS722020ALA330 (2TB);
    2 of Seagate Desktop ST4000DM000-1F2168 (4TB)
    PSU
    Corsair AX850 Gold
    Case
    Cooler Master HAF 932 Advanced
    Cooling
    ThermalTake Silent 1156
    Keyboard
    Logitech K520
    Mouse
    Logitech M310
    Internet Speed
    7Mbps
    Browser
    Chrome
    Antivirus
    Kaspersky
    Other Info
    Event Studio Precision 6 powered audio monitors;
    Boston Acoustics CS Sub 10 Powered Subwoofer;
    NI Kore controller;
    NI Maschine controller;
    M-Audio Axiom 61 keyboard controller; expression pedal; sustain pedal;

    ... and tons of audio software ...

    I also keep two USB 3 thumb drives (A: and B:) attached with boot recovery and security stuff that I can boot into from BIOS in case of emergency
Bit of an old post I know but did anyone get to the bottom of this ? No word from Microsoft , well not that I can find anyway.
 

My Computer

System One

  • OS
    Win 8 X64
    Computer type
    Laptop
    System Manufacturer/Model
    Acer Aspire E1-571 V2.09
    CPU
    Intel i5 Mobile 3230M
    Motherboard
    Acer EA50_HC_CR Type2
    Memory
    8 Gig DDR3
    Graphics Card(s)
    Intel HD 4000 Mobile
    Sound Card
    Realtek High Definition Audio
    Monitor(s) Displays
    Generic PnP Monitor (15.3"vis)
    Screen Resolution
    1378 x 768
    Hard Drives
    WDC WD5000BPVT-22A1YT0 [Hard drive] (500.11 GB)
    Cooling
    Standard Acer Laptop
    Keyboard
    Standard Acer Laptop
    Mouse
    Daffodil WMS330 Wireless Optical Mouse 2.4GHz
    Internet Speed
    Fast enough for p0rnz lol
    Browser
    Chrome (Latest Dev build)
    Antivirus
    Avast ~ Free
    Other Info
    Part time idiot and basement dweller ....So when you call me one its true lol.
I was having this same problem. Computer waking up about 20 seconds after being instructed to sleep. Very high number of 4797's in the Event Viewer. I tried disallowing my mouse to wake the computer. The problem seems to have gone away. The funny thing is that clicking the mouse still wakes the computer, but now it actually stays asleep. Now I am only seeing 4797 events corresponding to actual keystrokes or mouse clicks used to wake the machine.
 

My Computer

System One

  • OS
    Windows 8.0
You r stuck in Audit mode.

I reinstalled my operating system just today, and it did not require me to accept the terms. That's the first sign of Audit Mode (explaining what Audit mode is after). So I went to Event Logs and saw the EXACT error. So I went to sysprep and made it generalize and enter OOBE (Out of box experience, when u buy a new computer. But then, IT MAKES EXACT ERROR!!!
Audit mode is so that the manufacturer can SECRETLY and UNTRACEABLY install stuff. It's been around from XP, 12 years ago, with Sysprep.

So now the problem lies with Windows. The Event ID 4797, or (An attempt was made to query the existence of a blank password for an account.)is part of the symptoms for being Stuck In Audit Mode.

So, to solve this, figure out how to turn Audit Mode off.

My computer is a NP300E5C-A07US, the Thanksgiving Best Buy Combo Model.
 
Last edited:

My Computer

System One

  • OS
    Windows 8 Core 64-bit
    Computer type
    Laptop
    System Manufacturer/Model
    Samsung NP300E5C-A07US
    CPU
    Intel Core i3-2370M
    Motherboard
    HM75 Chipset
    Memory
    4GB
    Graphics Card(s)
    Intel HD Graphics 3000
    Browser
    Firefox
    Antivirus
    AVG Antivirus Free
Strategy

Okay, it sounds like we want to know if the originating software (for the Event 4797) is local to the machine (and a Microsoft-related activity) or is not local to the machine and therefore probably a hacker.

Try this:
1) First, go into Computer Management -> Local Users and Groups and review your existing users. Note whether or not Administrator, Guest and HomeGroupUser$ are disabled or not. You might also note whether or not the default users are renamed or not.
2) Also, go into Event Viewer -> Event Viewer (Local) -> Windows Logs -> Security -> (go to one of the Event 4797 log events) -> look at Additional Information, Target Account Name and verify that it's "Administrator"
3) Local Group Policy Editor -> Local Computer Policy -> Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Accounts: Rename administrator account = Administrator

You might try renaming the Administrator account to AdminTest, rebooting your computer and waiting maybe ten minutes.

In theory, if the culprit is something like Microsoft Security Essentials (Windows Defender) or whatever audits the group/local policies then it will know that the administrator account has been changed and it should now create audit events for 4797 which mention AdminTest in the Additional Information area of the Event Log detail.

If the culprit is external to your system then in theory it would have no means of knowing that you'd changed the admin's name and would continue to query "Administrator". This then might be a good litmus test for determining if the originating software is local or remote. If the culprit is local then you might also infer that it's either Microsoft or non-Microsoft based upon this knowledge. (You can of course rename your admin user when you're finished with this test.)

Good luck,
Albus
 

My Computer

System One

  • OS
    Windows 8.1 Pro
    Computer type
    Laptop
    System Manufacturer/Model
    HP
    Browser
    Internet Explorer 11
    Antivirus
    Microsoft Defender (MSE)
Is there a solution to this long standing issue which appears to be a 'feature' of Windows 8? I checked both my PCs running Windows 8.1 x64 and both have the same frequent reports of Event ID4797.

Is there a way of just disabling the checking of the existence of a blank password to prevent these events filling up the log file?
 

My Computer

System One

  • OS
    Windows 8.1 64 bit
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Home Build
    CPU
    Intel i3570K
    Motherboard
    Gigabyte GA-77X-UD5H
    Memory
    16 GB
    Graphics Card(s)
    Sapphire R9 280X Toxic
    Sound Card
    Realtek on motherboard
    Monitor(s) Displays
    Viewsonic VP2770
    Screen Resolution
    2560 x 1440
    Hard Drives
    Intel 520 180GB SSD
    Seagate 2T HDD
    Seagate external 1T USB HDD
    PSU
    XFX 850W
    Case
    Nanoxia Deep Silence 1
    Cooling
    Noctua NH-D14
    Keyboard
    Microsoft
    Mouse
    Microsoft
    Internet Speed
    50Mbps
    Browser
    Chrome
Back
Top