Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Windows Login Failure Audits

Posted on 2004-08-06
10
Medium Priority
?
2,465 Views
Last Modified: 2013-12-04
I have logon failure attempts to every account on my machine. Every account has 2. They are posted below. If anyone can help me know what is going on and how I can fix it, it will be much appreciated. Thx.

Logs:

Event ID: 529
Logon Failure:
       Reason:            Unknown user name or bad password
       User Name:      ASPNET
       Domain:            
       Logon Type:      2
       Logon Process:      Advapi  
       Authentication Package:      MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
       Workstation Name:      COMPUTER

Event ID: 680
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
 Logon account:  ASPNET
 Source Workstation: COMPUTER
 Error Code: 0xC000006A


0
Comment
Question by:planza
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 40

Accepted Solution

by:
Fatal_Exception earned 2000 total points
ID: 11741303
This will help explain it to you...

You receive a "logon failure: unknown user name or bad" error message while accessing remote security-enhanced resources from an ASP.NET application

http://support.microsoft.com/default.aspx?scid=kb;EN-US;842789

FE
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 11741306
BTW:  it will show you how to stop it from ocurring also..  :)
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 11741382
Try scanning your PC with an AV scanner, like Stinger
http://vil.nai.com/vil/stinger/
-rich
0
2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 11742395
Doubt seriously that it is a virii, but it does not hurt to ck.  This error is a common error, and can be fixed with the link provided above..

FE
0
 
LVL 1

Author Comment

by:planza
ID: 11744762
cool, thanks for the info. I will give you the points for that, but do you know how I can see exactly is trying to access something?

thx
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 11744844
You can use one of the workarounds in the article above to prevent these errors from ocurring...    A little complicated, but it is well documented..  Good luck..!!

And thank you..

FE
0
 
LVL 1

Author Comment

by:planza
ID: 11779309
yes, I read those and understand that. BUT I want to find out which program is CAUSING ther error, not just how to prevent the error from occuring.

I want to find the cause of the error.

Thanks
0
 

Expert Comment

by:kempt
ID: 11851995
Have you resolved this yet?  I'm seeing the same, and would love to read your results.
0
 
LVL 1

Author Comment

by:planza
ID: 12263568
no, still not resolved. I went through and disabled ALL accounts except fro the one that I use. I have to go and re-enable accts fro development etc, but this seems to have stopped the logevents...

I'll bet that there is some sort of software than can monitor this, maybe by symantec of sth...

let me know if oyu find anything
0
 

Expert Comment

by:mcnellie
ID: 12532745
I constantly over the last year or so get MS NT 4.0 Event Id 'chains' of 529, with a spoofed User name and Domain and the time of events sometimes seconds apart. It appears as a 'propagated type of NETBIOS/SMB automated program " and I've tried "anon logon restrictions" but they still reappear in large groups?

Any tips, guidance or advice would be greatly appreciated!
J. McNellie
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The term "Bad USB" is a buzz word that is usually used when talking about attacks on computer systems that involve USB devices. In this article, I will show what possibilities modern windows systems (win8.x and win10) offer to fight these attacks wi…
SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Add bar graphs to Access queries using Unicode block characters. Graphs appear on every record in the color you want. Give life to numbers. Hopes this gives you ideas on visualizing your data in new ways ~ Create a calculated field in a query: …
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question