Reviewing log windows 2008 r2, found that windows 7 from two computer are constantly trying to start session. I spent antivirus, antispyware, malware, etc. and detects any virus, Trojan, worm, on computers. you can
help solve who is making these requests and how to eliminate.
The port is changing from 50 to 65000. attached log message
Thanks
Audit Failure Audit 29/05/2013 8:53:02 Microsoft Windows security. 4625 Login
Audit Failure Audit 29/05/2013 8:50:32 Microsoft Windows security. 4625 Login
Error on login account.
Subject:
Security ID: NULL SID
Account name: -
Account Domain: -
Logon ID: 0x0
Logon Type 3
Features error log:
Security ID: NULL SID
Account Name: MARIA-PC $
Account Domain: VFM1
Error Information:
Reason for failure: unknown user name or bad password
Status: 0xc000006d
Substate: 0xc0000064
Process information:
Process ID of the caller: 0x0
Process name of caller: -
Information Network:
Workstation Name: MARY-PC
Source Network Address: 192.168.1.207
Port: 50506
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0
The port is changing from 50 to 65000. attached log message
Thanks
Audit Failure Audit 29/05/2013 8:53:02 Microsoft Windows security. 4625 Login
Audit Failure Audit 29/05/2013 8:50:32 Microsoft Windows security. 4625 Login
Error on login account.
Subject:
Security ID: NULL SID
Account name: -
Account Domain: -
Logon ID: 0x0
Logon Type 3
Features error log:
Security ID: NULL SID
Account Name: MARIA-PC $
Account Domain: VFM1
Error Information:
Reason for failure: unknown user name or bad password
Status: 0xc000006d
Substate: 0xc0000064
Process information:
Process ID of the caller: 0x0
Process name of caller: -
Information Network:
Workstation Name: MARY-PC
Source Network Address: 192.168.1.207
Port: 50506
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0