Event ID - 4659

Event Id4659
SourceMicrosoft-Windows-Security-Auditing
DescriptionA handle to an object was requested with intent to delete.

Subject:
      Security ID:<Security ID>
      Account Name:<Account Name>
      Account Domain:<Domain name>
      Logon ID:<Logon ID>     

Object:
      Object Server:<Object Server>
      Object Type:<Object Type>
      Object Name:<Object Name>
      Handle ID:<Handle ID>     

Process Information:
      Process ID: <Process ID>
      Access Request Information:
      Transaction ID:<Transaction ID>
      Accesses: <Accesses>
      Access Mask:<Access Mask>
      Privileges Used for Access Check:

Event InformationCause :
This event should be logged whenever user install a patch that requires replacement of a file that is already opened by Windows and can't be closed until shut down.
Reference Links

Catch threats immediately

We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.

See what we caught

Did this information help you to resolve the problem?

Yes: My problem was resolved.
No: The information was not helpful / Partially helpful.