Quantcast
Channel: Security forum
Viewing all articles
Browse latest Browse all 12072

Audit Failure Microsoft Windows security. 4625 Login

$
0
0
Reviewing log windows 2008 r2, found that windows 7 from two computer are constantly trying to start session. I spent antivirus, antispyware, malware, etc. and detects any virus, Trojan, worm, on computers. you can help solve who is making these requests and how to eliminate.

The port is changing from 50 to 65000. attached log message

 

Thanks

 

Audit Failure Audit 29/05/2013 8:53:02 Microsoft Windows security. 4625 Login

Audit Failure Audit 29/05/2013 8:50:32 Microsoft Windows security. 4625 Login

 

 

Error on login account.

 

Subject:

                
Security ID: NULL SID

                
Account name: -

                
Account Domain: -

                
Logon ID: 0x0

 

Logon Type 3

 

Features error log:

                
Security ID: NULL SID

                
Account Name: MARIA-PC $

                
Account Domain: VFM1

 

Error Information:

                
Reason for failure: unknown user name or bad password

                
Status: 0xc000006d

                
Substate: 0xc0000064

 

Process information:

                
Process ID of the caller: 0x0

                
Process name of caller: -

 

Information Network:

                
Workstation Name: MARY-PC

                
Source Network Address: 192.168.1.207

                
Port: 50506

 

Detailed Authentication Information:

                
Logon Process: NtLmSsp

                
Authentication Package: NTLM

                
Transited Services: -

                
Package Name (NTLM only): -

                
Key Length: 0

Viewing all articles
Browse latest Browse all 12072

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>