HI I found these entry in my event viewer:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 3/2/2004
Time: 10:00:19 AM
User: NT111B\IUSR_NT111B
Computer: NT111B
Description:
Object Open:
Object Server: SC Manager
Object Type: SC_MANAGER OBJECT
Object Name: ServicesActive
New Handle ID: -
Operation ID: {0,135163196}
Process ID: 288
Primary User Name: NT111B$
Primary Domain: CMPASIA
Primary Logon ID: (0x0,0x3E7)
Client User Name: IUSR_NT111B
Client Domain: NT111B
Client Logon ID: (0x0,0x642BB2D)
Accesses READ_CONTROL
Connect to service controller
Lock service database for exclusive access
Privileges -
--------------------------
----------
----------
----------
----------
----------
----------
-----
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 681
Date: 3/2/2004
Time: 8:00:50 AM
User: NT AUTHORITY\SYSTEM
Computer: NT111B
Description:
The logon to account: service_password=
by: MICROSOFT_AUTHENTICATION_P
ACKAGE_V1_
0
from workstation: NT111B
failed. The error code was: 3221225572
--------------------------
----------
----------
----------
----------
----------
----------
----------
----------
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 3/2/2004
Time: 8:00:50 AM
User: NT AUTHORITY\SYSTEM
Computer: NT111B
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: service_password=
Domain:
Logon Type: 5
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_P
ACKAGE_V1_
0
Workstation Name: NT111B
--------------------------
----------
----------
----------
----------
----------
----------
----------
-----
Seems like some malicious activity. Is there anyone out there who can shed some light on this? Thank you.
Start Free Trial