Hi everybody,
Im using windows server 2008 (v6.0.6002) as a IIS and File Services Server. SQL Server 2008 and Office 2003 are installed.
I am trying to resolve a logon failure that is happening exactly every 2 minutes since I installed Office 2003 and SQL Server 2008.
Everything seems to work fine but I don't know how can I find out what program/service is trying to log on as root every 2 min.
Any ideas of what's happening here? I'd appreciate any help!! :D
Thanks!
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 3/5/2012 2:08:31 PM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: <<MyComputerName>>
Description:
An account failed to log on.
Subject:
Security ID: SYSTEM
Account Name: <<MyComputerName>>$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon Type: 2
Account For Which Logon Failed:
Security ID: NULL SID
Account Name: root
Account Domain: <<MyComputerName>>
Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xc000006d
Sub Status: 0xc000006a
Process Information:
Caller Process ID: 0x268
Caller Process Name: C:\Windows\System32\winlogon.exe
Network Information:
Workstation Name: <<MyComputerName>>
Source Network Address: 127.0.0.1
Source Port: 0
Detailed Authentication Information:
Logon Process: User32
Authentication Package: Negotiate
Transited Services: -
Package Name (NTLM only): -
Key Length: