Solved

SO MANY success audit entries in the Event Viewer Security Log

Posted on 2004-08-11
3
1,378 Views
Last Modified: 2013-12-04
Hi.

WHile trying to see why/when a users sign on got locked out, i was looking thru the Event Viewer / Security log.

Seems there were a ton, I mean A TON of Success Audit from very late night from a multitude of pc's that i know users are not signing onto.  
 
Most entries are :
ID 540 - Successful Network Logon
ID 538 - User Logoff
ID 680 - Account used for logon by

Does anyone know why so many entries that shouldnt be?

thanks.

ST
0
Comment
Question by:ststst
3 Comments
 
LVL 2

Expert Comment

by:chuckatwork
ID: 11779683
Maybe try logon hour restrictions for the account in AD to troubleshoot. Just find the user in AD and there is an hour logon restriction tab. Could they be running scripts? Can you turn off a user's computer to see if it appears that night?
0
 
LVL 12

Accepted Solution

by:
alandc earned 100 total points
ID: 12227457
I would suggest that the computer is infected with some trojan, spyware, or virus that is attempting to replicate across the network. Does the user log off their comptuer in the evening when they leave? If the activity is legitimate it might be their desktop antivirus scanning network drives or some other such searching or indexing function. We always have users reboot or logoff their computer but not shut them down so we can administer updates during the late/early hours.
0

Featured Post

Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

Join & Write a Comment

Recently, a new law in my state forced us to get a top-to-bottom analysis of all of our contract client's networks. While we have documentation, it was spotty at best for some - and in any event it needed to be checked against reality. That was m…
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now