[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

9.1

Failed Audit - Event ID 680

Asked by WPHIT in Networking Security Vulnerabilities, Windows Network Security

Tags: Failed Audit Event Id 680 Windows Server 2003

Hi All,

We've noticed hundreds of failed logon attempts appear on the DC over the last 24 hours. Event ID below:

"Logon attempt by:      MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 Logon account:      `bjeiVlak[]Y_bUUbY
 Source Workstation:      Workstationname
 Error Code:      0xC0000064"

The Workstation name is genuine but the logon account certainly isn't. This has been happening for about 60 machines. Our Workstations are Windows XP SP3 and the Servers run Windows Server 2003 R2.

We've scanned all the machines with Sophos and it removed xCmdSvc from the system32 directory on the XP desktops, but it then comes back. I guess we have a worm somewhere on the network but we can't seem to stop it propagating and remove it.

The Firewall to the outside world has always had port 445 blocked so i'm not sure it's replated to the iraq oil worm that's prominent on most searches.

I've enabled logon auditing on the DC and netlogon.log shows hundreds of lines very similar to the below:
10/02 15:26:19 [LOGON] ADMIN: SamLogon: Transitive Interactive logon of (null)\`bjeiVlak[]Y_bUUbY from workstationname1 (via workstationname1) Entered
10/02 15:26:19 [LOGON] ADMIN: NlPickDomainWithAccount: `bjeiVlak[]Y_bUUbY: Algorithm entered. UPN:0 Sam:0 Exp:0 Cross: 0 Root:1 DC:0
10/02 15:26:19 [LOGON] ADMIN: SamLogon: Transitive Interactive logon of (null)\`bjeiVlak[]Y_bUUbY from workstationname1 (via workstationname1) Returns 0xC0000064
10/02 15:26:20 [LOGON] ADMIN: SamLogon: Transitive Interactive logon of (null)\`bjeiVlak[]Y_bUUbY from workstationname3 (via workstationname3) Entered
10/02 15:26:20 [LOGON] ADMIN: NlPickDomainWithAccount: `bjeiVlak[]Y_bUUbY: Algorithm entered. UPN:0 Sam:0 Exp:0 Cross: 0 Root:1 DC:0
10/02 15:26:20 [LOGON] ADMIN: SamLogon: Transitive Interactive logon of (null)\`bjeiVlak[]Y_bUUbY from workstationname3 (via workstationname3) Returns 0xC0000064

These logs don't really help me much as i'd ideally have expected to see what machine the request came from.

When we clean the xCmdSvc from the system32 directory, another pc gets a copy of the same file in it's system32 directory to replace it. Netstat shows internal port 445 being used and the PC shows a connection to it's ipc$ share, but no clue as to where it came from.

We've got Sophos set to scan on read/write/access etc.. and on it's most through settings, so this has stopped the xCmdSvc.exe being wrote to most of the machines, although I can still see the attempts there.

Any ideas how we can track down the source of this and stop it running?

Cheers

[+][-]10/03/09 08:23 AM, ID: 25485672Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/05/09 04:52 AM, ID: 25494307Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/05/09 05:56 PM, ID: 25501171Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]10/08/09 03:11 AM, ID: 25523614Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10/08/09 05:32 AM, ID: 25524607Accepted Solution

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

About this solution

Zones: Networking Security Vulnerabilities, Windows Network Security
Tags: Failed Audit Event Id 680 Windows Server 2003
Sign Up Now!
Solution Provided By: jfer0x01
Participating Experts: 1
Solution Grade: A
 
[+][-]10/13/09 04:55 PM, ID: 25566027Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-89 - Hierarchy / EE_QW_3_20080625