﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 628 - User Account password set  / Event ID 628: Password reset by NTAUTHORITY\System / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 17 May 2012 09:03:09 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Event ID 628: Password reset by NTAUTHORITY\System</title><link>http://forum.ultimatewindowssecurity.com/Topic414-75-1.aspx</link><description>I missed seeing this question unitl now.  Whose password was reset?  Check the Target Account Name</description><pubDate>Sat, 28 Aug 2010 17:02:52 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Event ID 628: Password reset by NTAUTHORITY\System</title><link>http://forum.ultimatewindowssecurity.com/Topic414-75-1.aspx</link><description>Hi,&lt;P&gt;on several Windows XP SP3 Clients we found event ID 628 together with event ID 642. The caller's username in both eventlog entries is computername$ (NTAUTHORITY\System).&lt;/P&gt;&lt;P&gt;We assume that some unauthoritzed users gained local admin rights on their machines and that those entries have something to do with it. What does it mean if the caller of an ID 628 is NTAuthority\System?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Dago</description><pubDate>Mon, 12 Jul 2010 01:24:54 GMT</pubDate><dc:creator>dago1010</dc:creator></item></channel></rss>
