cancel
Showing results for 
Search instead for 
Did you mean: 

Events 4672 & 4624 Win 10 Freezes - special LOGON ? (ROG Strix Z390-H Gaming)

austnaaron
Level 7
HI All - Need your help.

My window 10 machine continues to freeze for 5-30 seconds intermittently. This happens randomly, but always comes with posts to the System Event handler of these two errors: 4672 & 4624 - essentially something on the board decides it needs elevated permission, and the whole system freezes until this is granted. Sometimes for up to 30 seconds. It makes gaming with this rig impossible. Then the machine will recover. Then in anothes 20 minutes to an hour, it happens again .
It doesn't matter what I'm doing, whether i'm editing a document or playing world of warcraft (so its not about taxing my graphics).

Anyone else have this issue? Anyone else RESOLVE this issue? Microsoft punted on the issue and said it was clearly a motherboard thing.

I am running with a win 10 boot drive on an M2 SSD, which seems to be a common thread of most people having this issue.

32 gb ram,
ROG STRIX 290Z-H Gaming mother board, Intel, i7-9700 CPU 3.60 Ghz
64 bit windows 10 x64 bit processor

using onboard graphics and using onboard Networking
Using a GeForce GTX 1060 6 GB video

78377

I have already done the SFC scan, and the reset/validation of all system files. didn't fix it.

It's a brand new win 10 / 64 bit install, so there is nothing in our way from an older install.

So... how do I resolve this? I've attached the event records that were generated at the time of the event below.

Help!

Aaron

''''''''''''''''''''

- System
- Provider
[ Name] Microsoft-Windows-Security-Auditing
[ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}
EventID 4672
Version 0
Level 0
Task 12548
Opcode 0
Keywords 0x8020000000000000
- TimeCreated
[ SystemTime] 2019-01-17T13:18:33.562408900Z
EventRecordID 37510
- Correlation
[ ActivityID] {b7b4670b-ac8e-0003-1b67-b4b78eacd401}
- Execution
[ ProcessID] 968
[ ThreadID] 1080
Channel Security
Computer DESKTOP-2UPSH75
Security
- EventData
SubjectUserSid S-1-5-18
SubjectUserName SYSTEM
SubjectDomainName NT AUTHORITY
SubjectLogonId 0x3e7
PrivilegeList SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege
================================

- System
- Provider
[ Name] Microsoft-Windows-Security-Auditing
[ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d}
EventID 4624
Version 2
Level 0
Task 12544
Opcode 0
Keywords 0x8020000000000000
- TimeCreated
[ SystemTime] 2019-01-17T13:11:32.382839600Z
EventRecordID 37507
- Correlation
[ ActivityID] {b7b4670b-ac8e-0003-1b67-b4b78eacd401}
- Execution
[ ProcessID] 968
[ ThreadID] 7424
Channel Security
Computer DESKTOP-2UPSH75
Security
- EventData
SubjectUserSid S-1-5-18
SubjectUserName DESKTOP-2UPSH75$
SubjectDomainName WORKGROUP
SubjectLogonId 0x3e7
TargetUserSid S-1-5-18
TargetUserName SYSTEM
TargetDomainName NT AUTHORITY
TargetLogonId 0x3e7
LogonType 5
LogonProcessName Advapi
AuthenticationPackageName Negotiate
WorkstationName -
LogonGuid {00000000-0000-0000-0000-000000000000}
TransmittedServices -
LmPackageName -
KeyLength 0
ProcessId 0x398
ProcessName C:\Windows\System32\services.exe
IpAddress -
IpPort -
ImpersonationLevel %%1833
RestrictedAdminMode -
TargetOutboundUserName -
TargetOutboundDomainName -
VirtualAccount %%1843
TargetLinkedLogonId 0x0
ElevatedToken %%1842
2,873 Views
0 REPLIES 0