I am seeing some "events" occuring on my computer during times when I am not using it (the middle of the night). I do not understand the Microsoft explanations of the events. Is this normal to see something like this in the event viewer under the security menu: type: success audit category: privilege use event: 576 user: network service and this type: success audit category: logon/logoff event: 528 user: network service Is this spyware or someone logging onto my machine ??? Thanks for any help
Not spyware, they are perfectly normal audit events for the network service user. Many background services run as "network service". This is a built in user/service name. In affect it is someone logging in/out but only to validate the server user from an audit perspective. If it failed then I would be concerned. You see it some on standalone pc's but it's very common to see that event in the logs of domain controllers. fwiw Bsulli