Those events are entirely normal - they appear even on a completely fresh machine. Today I discovered that an event is logged for each local account every time one of these two things happens:
- The username/picture tile in the upper-right of the Start screen is pressed. The events are logged even on domain-joined machines where the resulting menu contains no local users. In this case, the Subject is the logged-in user.
- The logon screen shows the list of active local users. In this case, the Subject is NT AUTHORITY\LOCAL SERVICE.
What happens when neither of those two situations are present, and your computer is still showing an ENORMOUS trail of these event logs?
ReplyDelete