M
Mark
We have been getting 100's of these Failure Audit logs on a daily
basis in our security event log for the past couple weeks. They are
showing up on our win 2000 sp4 application/database server. The user
is a current domain user but not a local user on the server. The
workstation however is not in our domain. What is bothering me is
that is trying to login from a machine that has the same name as a
current user. I have scanned for viruses and spyware on both the
server and the user's workstation, but came up empty on both searches.
The server is part of a 2000 domain and the user logs into a NT
domain. The user doesn't have a mapped drive to the server, but
accesses our main application that resides on the server on a daily
basis.
Below is an example of what we have been seeing.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 6/11/2004
Time: 6:12:17 AM
User: NT AUTHORITY\SYSTEM
Computer: Server-1 <---(Application/DB server)
Description:
The logon to account: NICKH <---(current user)
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: \\NICKH <---(not a current workstation)
failed. The error code was: 3221225572
Thanks in advance for any advise,
basis in our security event log for the past couple weeks. They are
showing up on our win 2000 sp4 application/database server. The user
is a current domain user but not a local user on the server. The
workstation however is not in our domain. What is bothering me is
that is trying to login from a machine that has the same name as a
current user. I have scanned for viruses and spyware on both the
server and the user's workstation, but came up empty on both searches.
The server is part of a 2000 domain and the user logs into a NT
domain. The user doesn't have a mapped drive to the server, but
accesses our main application that resides on the server on a daily
basis.
Below is an example of what we have been seeing.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 6/11/2004
Time: 6:12:17 AM
User: NT AUTHORITY\SYSTEM
Computer: Server-1 <---(Application/DB server)
Description:
The logon to account: NICKH <---(current user)
by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
from workstation: \\NICKH <---(not a current workstation)
failed. The error code was: 3221225572
Thanks in advance for any advise,