This event may be recorded when Terminal Services (TS) Client is used to access a server. Windows 2008 does not support themes over TS connections. If this is the case, the themes should be disabled on the server.
Even though this event is "Information" only, in many cases, it is recorded along with event id 9009 which is an "Error".
Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net.
Obtain enhanced visibility into Cisco ASA firewall logs using the free Firegen for Cisco ASA Splunk App. Take advantage of dashboards built to optimize the threat analysis process.