﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 4625 - An account failed to log on </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 17 May 2012 08:42:23 GMT</lastBuildDate><ttl>20</ttl><item><title>Status 0xc0000225</title><link>http://forum.ultimatewindowssecurity.com/Topic906-168-1.aspx</link><description>I found a scenario that generated a failure audit for Event 4625 using NTLM with excerpt as follows:&lt;p&gt;Failure Reason: An Error occured during Logon.&lt;/p&gt;&lt;p&gt;Status: 0xc0000225&lt;/p&gt;&lt;p&gt;Sub Status: 0x0&lt;/p&gt;&lt;p&gt;This occurred attempting to connect a CIFS mount from Red-Hat Linux to Windows Server 2008 R2. The mount had worked in Server 2003 but failed on 2008 R2. I discovered the following registry hotfix that addresses the issue which I confirmed with a network trace was exactly as described in KB 957441:&lt;/p&gt;&lt;p&gt;Client connections return a "STATUS_INVALID_PARAM" error code when you use a "Send NTLMv2 response only" authentication level in Windows Server 2008 or in Windows Vista&lt;/p&gt;&lt;p&gt;&lt;a href="http://support.microsoft.com/kb/957441"&gt;http://support.microsoft.com/kb/957441&lt;/a&gt;&lt;/p&gt;&lt;p&gt;In this case the status seems to be a generic indicator of "something is wrong with the NTLM negotiation."</description><pubDate>Wed, 01 Feb 2012 18:02:44 GMT</pubDate><dc:creator>markyel</dc:creator></item><item><title>4625 for a workstation name</title><link>http://forum.ultimatewindowssecurity.com/Topic891-168-1.aspx</link><description>From the event log:&lt;br&gt;Account is 10THCONFROOM$&lt;br&gt;In the expanded text, I see: Security ID:  S-1-0-0   Account Name:  10THCONFROOM$&lt;br&gt;&lt;br&gt;What is up with invalid logins for a workstation?</description><pubDate>Fri, 06 Jan 2012 16:57:00 GMT</pubDate><dc:creator>okvol</dc:creator></item><item><title>7000 NULL SID 4625's in 3 Days</title><link>http://forum.ultimatewindowssecurity.com/Topic881-168-1.aspx</link><description>Server 2008 R2, over 7000 NULL SID Event ID 4625's in the last 3 days, none before that, with Source IPs in Greece, France, Switzerland, Croatia, Chicago picked at random from log. Using ports in the 55,000s, some below port 5000.  Account names range from Administrator to BESAdmin to user5 etc. No BESAdmin or user5 around these parts. Kinda creepy, how concerned should I be?&lt;br&gt;&lt;br&gt;Thanks&lt;br&gt;&lt;br&gt;An account failed to log on.&lt;br&gt;&lt;br&gt;Subject:&lt;br&gt;	Security ID:		SYSTEM&lt;br&gt;	Account Name:		SERVER1$&lt;br&gt;	Account Domain:		MYDOMAIN&lt;br&gt;	Logon ID:		0x3e7&lt;br&gt;&lt;br&gt;Logon Type:			10&lt;br&gt;&lt;br&gt;Account For Which Logon Failed:&lt;br&gt;	Security ID:		NULL SID&lt;br&gt;	Account Name:		BESAdmin&lt;br&gt;	Account Domain:		SERVER1&lt;br&gt;&lt;br&gt;Failure Information:&lt;br&gt;	Failure Reason:		Unknown user name or bad password.&lt;br&gt;	Status:			0xc000006d&lt;br&gt;	Sub Status:		0xc0000064&lt;br&gt;&lt;br&gt;Process Information:&lt;br&gt;	Caller Process ID:	0x12f0&lt;br&gt;	Caller Process Name:	C:\Windows\System32\winlogon.exe&lt;br&gt;&lt;br&gt;Network Information:&lt;br&gt;	Workstation Name:	SERVER1&lt;br&gt;	Source Network Address:	94.230.215.228&lt;br&gt;	Source Port:		53535&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;An account failed to log on.&lt;br&gt;&lt;br&gt;Subject:&lt;br&gt;	Security ID:		SYSTEM&lt;br&gt;	Account Name:		SERVER1$&lt;br&gt;	Account Domain:		MYDOMAIN&lt;br&gt;	Logon ID:		0x3e7&lt;br&gt;&lt;br&gt;Logon Type:			10&lt;br&gt;&lt;br&gt;Account For Which Logon Failed:&lt;br&gt;	Security ID:		NULL SID&lt;br&gt;	Account Name:		admin2&lt;br&gt;	Account Domain:		SERVER1&lt;br&gt;&lt;br&gt;Failure Information:&lt;br&gt;	Failure Reason:		Unknown user name or bad password.&lt;br&gt;	Status:			0xc000006d&lt;br&gt;	Sub Status:		0xc0000064&lt;br&gt;&lt;br&gt;Process Information:&lt;br&gt;	Caller Process ID:	0xa00&lt;br&gt;	Caller Process Name:	C:\Windows\System32\winlogon.exe&lt;br&gt;&lt;br&gt;Network Information:&lt;br&gt;	Workstation Name:	SERVER1&lt;br&gt;	Source Network Address:	79.247.123.109&lt;br&gt;	Source Port:		49348&lt;br&gt;&lt;br&gt;Detailed Authentication Information:&lt;br&gt;	Logon Process:		User32 &lt;br&gt;	Authentication Package:	Negotiate&lt;br&gt;	Transited Services:	-&lt;br&gt;	Package Name (NTLM only):	-&lt;br&gt;	Key Length:		0&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;An account failed to log on.&lt;br&gt;&lt;br&gt;Subject:&lt;br&gt;	Security ID:		SYSTEM&lt;br&gt;	Account Name:		SERVER1$&lt;br&gt;	Account Domain:		MYDOMAIN&lt;br&gt;	Logon ID:		0x3e7&lt;br&gt;&lt;br&gt;Logon Type:			10&lt;br&gt;&lt;br&gt;Account For Which Logon Failed:&lt;br&gt;	Security ID:		NULL SID&lt;br&gt;	Account Name:		user5&lt;br&gt;	Account Domain:		SERVER1&lt;br&gt;&lt;br&gt;Failure Information:&lt;br&gt;	Failure Reason:		Unknown user name or bad password.&lt;br&gt;	Status:			0xc000006d&lt;br&gt;	Sub Status:		0xc0000064&lt;br&gt;&lt;br&gt;Process Information:&lt;br&gt;	Caller Process ID:	0x860&lt;br&gt;	Caller Process Name:	C:\Windows\System32\winlogon.exe&lt;br&gt;&lt;br&gt;Network Information:&lt;br&gt;	Workstation Name:	SERVER1&lt;br&gt;	Source Network Address:	188.129.87.175&lt;br&gt;	Source Port:		60163&lt;br&gt;&lt;br&gt;Detailed Authentication Information:&lt;br&gt;	Logon Process:		User32 &lt;br&gt;	Authentication Package:	Negotiate&lt;br&gt;	Transited Services:	-&lt;br&gt;	Package Name (NTLM only):	-&lt;br&gt;	Key Length:		0</description><pubDate>Thu, 22 Dec 2011 01:37:45 GMT</pubDate><dc:creator>deeblock</dc:creator></item><item><title>Failure Reason: Unknown user name or bad password Status: 0xc000006d</title><link>http://forum.ultimatewindowssecurity.com/Topic868-168-1.aspx</link><description>We are constantly receiving event log errors that the authenticated account we use with Arcserve has a bad password or something. I have 10 servers with Arcserve installed on it and 5 of them are reporting this error at the top of every hour. They all use the same authentication account.&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;12&lt;/em&gt;/&lt;em class="t"&gt;07&lt;/em&gt;&lt;/em&gt;/&lt;em class="t"&gt;2011&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;09&lt;/em&gt;:&lt;em class="t"&gt;00&lt;/em&gt;&lt;/em&gt;:&lt;em class="t"&gt;34&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;AM&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;LogName&lt;/em&gt;=&lt;em class="t"&gt;Security&lt;/em&gt;&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;SourceName&lt;/em&gt;=&lt;em class="t"&gt;Microsoft&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;Windows&lt;/em&gt; &lt;em class="t"&gt;security&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;auditing&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;EventCode&lt;/em&gt;=&lt;em class="t"&gt;4625&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;EventType&lt;/em&gt;=&lt;em class="t"&gt;0&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Type&lt;/em&gt;=&lt;em class="t"&gt;Information&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;ComputerName&lt;/em&gt;=&lt;em class="t a"&gt;&lt;em class="t"&gt;SERVERDC3&lt;/em&gt;&lt;/em&gt;&lt;/em&gt;.OurDomain&lt;/em&gt;.&lt;em class="t"&gt;local&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;TaskCategory&lt;/em&gt;=&lt;em class="t"&gt;Logon&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;OpCode&lt;/em&gt;=&lt;em class="t"&gt;Info&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;RecordNumber&lt;/em&gt;=&lt;em class="t"&gt;70984967&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Keywords&lt;/em&gt;=&lt;em class="t"&gt;Audit&lt;/em&gt;&lt;/em&gt; &lt;em class="t a"&gt;&lt;em class="t"&gt;Failure&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Message&lt;/em&gt;=&lt;em class="t"&gt;An&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;account&lt;/em&gt; &lt;em class="t"&gt;failed&lt;/em&gt; &lt;em class="t"&gt;to&lt;/em&gt; &lt;em class="t"&gt;log&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;on&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt; &lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Subject&lt;/em&gt;:&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Security&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;ID&lt;/em&gt;:&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;S&lt;/em&gt;-&lt;em class="t"&gt;1&lt;/em&gt;&lt;/em&gt;-&lt;em class="t"&gt;5&lt;/em&gt;&lt;/em&gt;-&lt;em class="t"&gt;18&lt;/em&gt;&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Account&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Name&lt;/em&gt;:&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t a"&gt;&lt;em class="t"&gt;SERVERC3&lt;/em&gt;&lt;/em&gt;$&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Account&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Domain&lt;/em&gt;:&lt;/em&gt;	&lt;em&gt;OurDomain&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;ID&lt;/em&gt;:&lt;/em&gt;&lt;em class="t"&gt;0x3e7&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Type&lt;/em&gt;:&lt;/em&gt;&lt;em class="t"&gt;4&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Account&lt;/em&gt; &lt;em class="t"&gt;For&lt;/em&gt; &lt;em class="t"&gt;Which&lt;/em&gt; &lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Failed&lt;/em&gt;:&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Security&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;ID&lt;/em&gt;: &lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;S&lt;/em&gt;-&lt;em class="t"&gt;1&lt;/em&gt;&lt;/em&gt;-&lt;em class="t"&gt;0&lt;/em&gt;&lt;/em&gt;-&lt;em class="t"&gt;0&lt;/em&gt;&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Account&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Name&lt;/em&gt;:&lt;/em&gt;&lt;em class="t a"&gt;&lt;em class="t"&gt;causer&lt;/em&gt;&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Account&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Domain&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t a"&gt;&lt;em class="t"&gt;SERVERDC3&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t a"&gt;&lt;em class="t"&gt;Failure&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Information&lt;/em&gt;:&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t a"&gt;&lt;em class="t"&gt;Failure&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Reason&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;Unknown&lt;/em&gt; &lt;em class="t"&gt;user&lt;/em&gt; &lt;em class="t"&gt;name&lt;/em&gt; &lt;em class="t"&gt;or&lt;/em&gt; &lt;em class="t"&gt;bad&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;password&lt;/em&gt;.&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Status&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;0xc000006d&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Sub&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Status&lt;/em&gt;: &lt;/em&gt;&lt;em class="t"&gt;0xc0000064&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Process&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Information&lt;/em&gt;:&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Caller&lt;/em&gt; &lt;em class="t"&gt;Process&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;ID&lt;/em&gt;: &lt;/em&gt;&lt;em class="t"&gt;0x1434&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Caller&lt;/em&gt; &lt;em class="t"&gt;Process&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Name&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;C&lt;/em&gt;:&lt;/em&gt;\&lt;em class="t"&gt;Program&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Files&lt;/em&gt;\&lt;em class="t"&gt;CA&lt;/em&gt;&lt;/em&gt;\&lt;em class="t"&gt;SharedComponents&lt;/em&gt;&lt;/em&gt;\&lt;em class="t"&gt;ARCserve&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Backup&lt;/em&gt;\&lt;em class="t"&gt;UniAgent&lt;/em&gt;&lt;/em&gt;\&lt;em class="t"&gt;UnivAgent&lt;/em&gt;&lt;/em&gt;.&lt;em class="t"&gt;exe&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Network&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Information&lt;/em&gt;:&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Workstation&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Name&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t a"&gt;&lt;em class="t"&gt;SERVERDC3&lt;/em&gt;&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Source&lt;/em&gt; &lt;em class="t"&gt;Network&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Address&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;-&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Source&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Port&lt;/em&gt;:&lt;/em&gt;		&lt;em class="t"&gt;-&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Detailed&lt;/em&gt; &lt;em class="t"&gt;Authentication&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Information&lt;/em&gt;:&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Process&lt;/em&gt;:&lt;/em&gt;		&lt;em class="t"&gt;Advapi&lt;/em&gt;  	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Authentication&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Package&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;Negotiate&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Transited&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Services&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;-&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Package&lt;/em&gt; &lt;em class="t"&gt;Name&lt;/em&gt; (&lt;em class="t"&gt;NTLM&lt;/em&gt; &lt;em class="t"&gt;only&lt;/em&gt;)&lt;em class="t"&gt;:&lt;/em&gt;	&lt;em class="t"&gt;-&lt;/em&gt;	&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Key&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Length&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;0&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;This&lt;/em&gt; &lt;em class="t"&gt;event&lt;/em&gt; &lt;em class="t"&gt;is&lt;/em&gt; &lt;em class="t"&gt;generated&lt;/em&gt; &lt;em class="t"&gt;when&lt;/em&gt; &lt;em class="t"&gt;a&lt;/em&gt; &lt;em class="t"&gt;logon&lt;/em&gt; &lt;em class="t"&gt;request&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;fails&lt;/em&gt;.&lt;/em&gt; &lt;em class="t"&gt;It&lt;/em&gt; &lt;em class="t"&gt;is&lt;/em&gt; &lt;em class="t"&gt;generated&lt;/em&gt; &lt;em class="t"&gt;on&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;computer&lt;/em&gt; &lt;em class="t"&gt;where&lt;/em&gt; &lt;em class="t"&gt;access&lt;/em&gt; &lt;em class="t"&gt;was&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;attempted&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;Subject&lt;/em&gt; &lt;em class="t"&gt;fields&lt;/em&gt; &lt;em class="t"&gt;indicate&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;account&lt;/em&gt; &lt;em class="t"&gt;on&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;local&lt;/em&gt; &lt;em class="t"&gt;system&lt;/em&gt; &lt;em class="t"&gt;which&lt;/em&gt; &lt;em class="t"&gt;requested&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;logon&lt;/em&gt;.&lt;/em&gt; &lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;This&lt;/em&gt; &lt;em class="t"&gt;is&lt;/em&gt; &lt;em class="t"&gt;most&lt;/em&gt; &lt;em class="t"&gt;commonly&lt;/em&gt; &lt;em class="t"&gt;a&lt;/em&gt; &lt;em class="t"&gt;service&lt;/em&gt; &lt;em class="t"&gt;such&lt;/em&gt; &lt;em class="t"&gt;as&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;Server&lt;/em&gt; &lt;em class="t"&gt;service&lt;/em&gt;, &lt;em class="t"&gt;or&lt;/em&gt; &lt;em class="t"&gt;a&lt;/em&gt; &lt;em class="t"&gt;local&lt;/em&gt; &lt;em class="t"&gt;process&lt;/em&gt; &lt;em class="t"&gt;such&lt;/em&gt; &lt;em class="t"&gt;as&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Winlogon&lt;/em&gt;.&lt;em class="t"&gt;exe&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;or&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Services&lt;/em&gt;.&lt;em class="t"&gt;exe&lt;/em&gt;&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;Type&lt;/em&gt; &lt;em class="t"&gt;field&lt;/em&gt; &lt;em class="t"&gt;indicates&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;kind&lt;/em&gt; &lt;em class="t"&gt;of&lt;/em&gt; &lt;em class="t"&gt;logon&lt;/em&gt; &lt;em class="t"&gt;that&lt;/em&gt; &lt;em class="t"&gt;was&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;requested&lt;/em&gt;.&lt;/em&gt; &lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;most&lt;/em&gt; &lt;em class="t"&gt;common&lt;/em&gt; &lt;em class="t"&gt;types&lt;/em&gt; &lt;em class="t"&gt;are&lt;/em&gt; &lt;em class="t"&gt;2&lt;/em&gt; (&lt;em class="t"&gt;interactive&lt;/em&gt;) &lt;em class="t"&gt;and&lt;/em&gt; &lt;em class="t"&gt;3&lt;/em&gt; (&lt;em class="t"&gt;network&lt;/em&gt;)&lt;em class="t"&gt;. &lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;Process&lt;/em&gt; &lt;em class="t"&gt;Information&lt;/em&gt; &lt;em class="t"&gt;fields&lt;/em&gt; &lt;em class="t"&gt;indicate&lt;/em&gt; &lt;em class="t"&gt;which&lt;/em&gt; &lt;em class="t"&gt;account&lt;/em&gt; &lt;em class="t"&gt;and&lt;/em&gt; &lt;em class="t"&gt;process&lt;/em&gt; &lt;em class="t"&gt;on&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;system&lt;/em&gt; &lt;em class="t"&gt;requested&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;logon&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;Network&lt;/em&gt; &lt;em class="t"&gt;Information&lt;/em&gt; &lt;em class="t"&gt;fields&lt;/em&gt; &lt;em class="t"&gt;indicate&lt;/em&gt; &lt;em class="t"&gt;where&lt;/em&gt; &lt;em class="t"&gt;a&lt;/em&gt; &lt;em class="t"&gt;remote&lt;/em&gt; &lt;em class="t"&gt;logon&lt;/em&gt; &lt;em class="t"&gt;request&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;originated&lt;/em&gt;.&lt;/em&gt; &lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Workstation&lt;/em&gt; &lt;em class="t"&gt;name&lt;/em&gt; &lt;em class="t"&gt;is&lt;/em&gt; &lt;em class="t"&gt;not&lt;/em&gt; &lt;em class="t"&gt;always&lt;/em&gt; &lt;em class="t"&gt;available&lt;/em&gt; &lt;em class="t"&gt;and&lt;/em&gt; &lt;em class="t"&gt;may&lt;/em&gt; &lt;em class="t"&gt;be&lt;/em&gt; &lt;em class="t"&gt;left&lt;/em&gt; &lt;em class="t"&gt;blank&lt;/em&gt; &lt;em class="t"&gt;in&lt;/em&gt; &lt;em class="t"&gt;some&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;cases&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;The&lt;/em&gt; &lt;em class="t"&gt;authentication&lt;/em&gt; &lt;em class="t"&gt;information&lt;/em&gt; &lt;em class="t"&gt;fields&lt;/em&gt; &lt;em class="t"&gt;provide&lt;/em&gt; &lt;em class="t"&gt;detailed&lt;/em&gt; &lt;em class="t"&gt;information&lt;/em&gt; &lt;em class="t"&gt;about&lt;/em&gt; &lt;em class="t"&gt;this&lt;/em&gt; &lt;em class="t"&gt;specific&lt;/em&gt; &lt;em class="t"&gt;logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;request&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;	&lt;em class="t"&gt;-&lt;/em&gt; &lt;em class="t"&gt;Transited&lt;/em&gt; &lt;em class="t"&gt;services&lt;/em&gt; &lt;em class="t"&gt;indicate&lt;/em&gt; &lt;em class="t"&gt;which&lt;/em&gt; &lt;em class="t"&gt;intermediate&lt;/em&gt; &lt;em class="t"&gt;services&lt;/em&gt; &lt;em class="t"&gt;have&lt;/em&gt; &lt;em class="t"&gt;participated&lt;/em&gt; &lt;em class="t"&gt;in&lt;/em&gt; &lt;em class="t"&gt;this&lt;/em&gt; &lt;em class="t"&gt;logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;request&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;	&lt;em class="t"&gt;-&lt;/em&gt; &lt;em class="t"&gt;Package&lt;/em&gt; &lt;em class="t"&gt;name&lt;/em&gt; &lt;em class="t"&gt;indicates&lt;/em&gt; &lt;em class="t"&gt;which&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;sub&lt;/em&gt;-&lt;em class="t"&gt;protocol&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;was&lt;/em&gt; &lt;em class="t"&gt;used&lt;/em&gt; &lt;em class="t"&gt;among&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;NTLM&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;protocols&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;	&lt;em class="t"&gt;-&lt;/em&gt; &lt;em class="t"&gt;Key&lt;/em&gt; &lt;em class="t"&gt;length&lt;/em&gt; &lt;em class="t"&gt;indicates&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;length&lt;/em&gt; &lt;em class="t"&gt;of&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;generated&lt;/em&gt; &lt;em class="t"&gt;session&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;key&lt;/em&gt;.&lt;/em&gt; &lt;em class="t"&gt;This&lt;/em&gt; &lt;em class="t"&gt;will&lt;/em&gt; &lt;em class="t"&gt;be&lt;/em&gt; &lt;em class="t"&gt;0&lt;/em&gt; &lt;em class="t"&gt;if&lt;/em&gt; &lt;em class="t"&gt;no&lt;/em&gt; &lt;em class="t"&gt;session&lt;/em&gt; &lt;em class="t"&gt;key&lt;/em&gt; &lt;em class="t"&gt;was&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;requested&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;p&gt;=====&lt;/p&gt;&lt;p&gt;next error for the same server:&lt;/p&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;12&lt;/em&gt;/&lt;em class="t"&gt;07&lt;/em&gt;&lt;/em&gt;/&lt;em class="t"&gt;2011&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;09&lt;/em&gt;:&lt;em class="t"&gt;00&lt;/em&gt;&lt;/em&gt;:&lt;em class="t"&gt;34&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;AM&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;LogName&lt;/em&gt;=&lt;em class="t"&gt;Security&lt;/em&gt;&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Source&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Name&lt;/em&gt;=&lt;em class="t"&gt;Microsoft&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;Windows&lt;/em&gt; &lt;em class="t"&gt;security&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;auditing&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;EventCode&lt;/em&gt;=&lt;em class="t"&gt;4776&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;EventType&lt;/em&gt;=&lt;em class="t"&gt;0&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Type&lt;/em&gt;=&lt;em class="t"&gt;Information&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;ComputerName&lt;/em&gt;=SERVERD&lt;em class="t a"&gt;&lt;em class="t"&gt;C3&lt;/em&gt;&lt;/em&gt;&lt;/em&gt;.OurDomain&lt;/em&gt;.&lt;em class="t"&gt;local&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;TaskCategory&lt;/em&gt;=&lt;em class="t"&gt;Credential&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;Validation&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;OpCode&lt;/em&gt;=&lt;em class="t"&gt;Info&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;RecordNumber&lt;/em&gt;=&lt;em class="t"&gt;70984966&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Keywords&lt;/em&gt;=&lt;em class="t"&gt;Audit&lt;/em&gt;&lt;/em&gt; &lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t a"&gt;&lt;em class="t"&gt;Failure&lt;/em&gt;&lt;/em&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;Message&lt;/em&gt;=&lt;em class="t"&gt;The&lt;/em&gt;&lt;/em&gt; &lt;em class="t"&gt;computer&lt;/em&gt; &lt;em class="t"&gt;attempted&lt;/em&gt; &lt;em class="t"&gt;to&lt;/em&gt; &lt;em class="t"&gt;validate&lt;/em&gt; &lt;em class="t"&gt;the&lt;/em&gt; &lt;em class="t"&gt;credentials&lt;/em&gt; &lt;em class="t"&gt;for&lt;/em&gt; &lt;em class="t"&gt;an&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;account&lt;/em&gt;.&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Authentication&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Package&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;&lt;em class="t"&gt;MICROSOFT&lt;/em&gt;_&lt;em class="t"&gt;AUTHENTICATION&lt;/em&gt;&lt;/em&gt;_&lt;em class="t"&gt;PACKAGE&lt;/em&gt;&lt;/em&gt;_&lt;em class="t"&gt;V1&lt;/em&gt;&lt;/em&gt;_&lt;em class="t"&gt;0&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Logon&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Account&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t a"&gt;&lt;em class="t"&gt;causer&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Source&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Workstation&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t a"&gt;&lt;em class="t"&gt;SERVERDC3&lt;/em&gt;&lt;/em&gt;&lt;/pre&gt;&lt;pre class="event"&gt;&lt;em class="t"&gt;Error&lt;/em&gt; &lt;em class="t"&gt;&lt;em class="t"&gt;Code&lt;/em&gt;:&lt;/em&gt;	&lt;em class="t"&gt;0xc0000064&lt;/em&gt;&lt;/pre&gt;&lt;p&gt;&lt;br&gt;We have multiple servers with Arcserve, this error is occuring on a number of the servers, but not all of them. &lt;/p&gt;&lt;p&gt;The account used is a domain authenticated account and is used for all the servers with Arcserve installed. So we're trying to identify &lt;/p&gt;&lt;p&gt;why this error is occuring.&lt;/p&gt;&lt;p&gt;Version of ARCserve and OS:&lt;/p&gt;&lt;p&gt;OS is Windows server 2008 R2 with SP1, Arcserve version is 15R build 6222&lt;/p&gt;&lt;p&gt;Any suggestions are appreciated.&lt;/p&gt;&lt;p&gt;Roger</description><pubDate>Wed, 07 Dec 2011 10:51:08 GMT</pubDate><dc:creator>n5eea</dc:creator></item><item><title>0xc0000006d in Event 4625</title><link>http://forum.ultimatewindowssecurity.com/Topic774-168-1.aspx</link><description>Hi Randy,&lt;/P&gt;&lt;P&gt;You mention in the wiki for Event 4625 that 0xc0000006d "seems to be caused by system problems and non-security related." I'm not sure what this means. In Microsoft documentation, this code is stated as an attempted logon that is invalid due to bad username. Are you saying that you find this to be inaccurate/invalid for the new Vista and higher Event 4625 entries?&lt;/P&gt;&lt;P&gt;Many thanks.</description><pubDate>Mon, 01 Aug 2011 12:52:48 GMT</pubDate><dc:creator>markyel</dc:creator></item><item><title>Confusion between Status and Substatus codes</title><link>http://forum.ultimatewindowssecurity.com/Topic822-168-1.aspx</link><description>Dear Randy,&lt;P&gt;In the encyclopedia article on the event 4625, the first column of the table says 'Status and Sub status codes'. But, Status and Substatus have different values. I have observed this for wrong password event on a Windows 2008 machine. Please refer to the attached screen shot.&lt;/P&gt;&lt;P&gt;The value of Status is 0xc000006d and Sub Status is 0xc000006a.&lt;P&gt;So, in the encyclopedia article, are your referring to Sub Status codes for all the cases?&lt;P&gt; &lt;P&gt;Thanks,&lt;P&gt;Praveen</description><pubDate>Fri, 14 Oct 2011 07:52:52 GMT</pubDate><dc:creator>gurrapu.praveen</dc:creator></item><item><title>Wierd logs in a reghosted image of Windows 2008 R2 server</title><link>http://forum.ultimatewindowssecurity.com/Topic793-168-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;I have a Windows 2008 R2 Server machine which is reghosted from an image. It logs audit log events with Event ID: 4625, Sub-status code: 0xc0000064 and Event Type: 3. It logs these events at a frequency of atleast 10 events per minute. Is there any way to suppress these events?&lt;/P&gt;&lt;P&gt;Also, I am trying to generate a failed logon event on that machine. But, when I enter wrong credentials and check the event log, I don't find any event with Event Type 2. &lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Regards,&lt;BR&gt;Praveen</description><pubDate>Tue, 30 Aug 2011 09:53:40 GMT</pubDate><dc:creator>gurrapu.praveen</dc:creator></item><item><title>Event ID 4625 and NULL SID with 0xc000006d</title><link>http://forum.ultimatewindowssecurity.com/Topic606-168-1.aspx</link><description>Randy,&lt;br&gt;&lt;br&gt;I'm seeing the following events:&lt;br&gt;&lt;br&gt;Account For Which Logon Failed:&lt;br&gt;	Security ID:		NULL SID&lt;br&gt;	Account Name:		computername$&lt;br&gt;	Account Domain:		Domainname&lt;br&gt;&lt;br&gt;Failure Information:&lt;br&gt;	Failure Reason:		An Error occured during Logon.&lt;br&gt;	Status:			0xc000006d&lt;br&gt;	Sub Status:		0x0&lt;br&gt;&lt;br&gt;Something to worry about, or noise?&lt;br&gt;&lt;br&gt;Thx,&lt;br&gt;Jeff</description><pubDate>Thu, 24 Feb 2011 10:32:53 GMT</pubDate><dc:creator>jwalzer</dc:creator></item><item><title>4625 with Different Account Identifiers</title><link>http://forum.ultimatewindowssecurity.com/Topic707-168-1.aspx</link><description>Any idea what this means? I'm seeing 4625 errors on some of our 2008R2 servers where the Subject account is one of our administrators and the Account For Which Logon Failed is the disabled Guest account. Most of the erros reference &lt;span lang="EN"&gt;C:\Windows\explorer.exe but some reference the mmc.exe or printgui.exe. And the errors appear to be a recurring series; not a lot but ten or twelve every day, and generally , but not always, in the afternoon hours.&lt;/p&gt;&lt;/span&gt;&lt;p&gt;Thanks,&lt;/p&gt;&lt;p&gt;Ralph&lt;/p&gt;&lt;p&gt;--------&lt;/p&gt;&lt;span lang="EN"&gt;&lt;p&gt;An account failed to log on.&lt;/p&gt;&lt;p&gt;Subject:&lt;/p&gt;&lt;p&gt;	Security ID: 	XXXXXX\admin-zzzzzzzzz&lt;/p&gt;&lt;p&gt;	Account Name:		admin-zzzzzzzz&lt;/p&gt;&lt;p&gt;	Account Domain: 	XXXXXX&lt;/p&gt;&lt;p&gt;	Logon ID:		0x6dff9927&lt;/p&gt;&lt;p&gt;Logon Type:			3&lt;/p&gt;&lt;p&gt;Account For Which Logon Failed:&lt;/p&gt;&lt;p&gt;	Security ID:		NULL SID&lt;/p&gt;&lt;p&gt;	Account Name:		Guest&lt;/p&gt;&lt;p&gt;	Account Domain: 	YYYYY_FP&lt;/p&gt;&lt;p&gt;Failure Information:&lt;/p&gt;&lt;p&gt;	Failure Reason:		Account currently disabled.&lt;/p&gt;&lt;p&gt;	Status:			0xc000006e&lt;/p&gt;&lt;p&gt;	Sub Status:		0xc0000072&lt;/p&gt;&lt;p&gt;Process Information:&lt;/p&gt;&lt;p&gt;	Caller Process ID:	0xce4&lt;/p&gt;&lt;p&gt;	Caller Process Name:	C:\Windows\explorer.exe&lt;/p&gt;&lt;p&gt;Network Information:&lt;/p&gt;&lt;p&gt;	Workstation Name:	YYYYY_FP&lt;/p&gt;&lt;p&gt;	Source Network Address:	-&lt;/p&gt;&lt;p&gt;	Source Port:		-&lt;/p&gt;&lt;p&gt;Detailed Authentication Information:&lt;/p&gt;&lt;p&gt;	Logon Process:		Advapi  &lt;/p&gt;&lt;p&gt;	Authentication Package:	Negotiate&lt;/p&gt;&lt;p&gt;	Transited Services:	-&lt;/p&gt;&lt;p&gt;	Package Name (NTLM only):	-&lt;/p&gt;&lt;p&gt;	Key Length:		0&lt;/p&gt;&lt;p&gt;This event is generated when a logon request fails. It is generated on the computer where access was attempted.&lt;/p&gt;&lt;p&gt;The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.&lt;/p&gt;&lt;p&gt;The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).&lt;/p&gt;&lt;p&gt;The Process Information fields indicate which account and process on the system requested the logon.&lt;/p&gt;&lt;p&gt;The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.&lt;/p&gt;&lt;p&gt;The authentication information fields provide detailed information about this specific logon request.&lt;/p&gt;&lt;p&gt;	- Transited services indicate which intermediate services have participated in this logon request.&lt;/p&gt;&lt;p&gt;	- Package name indicates which sub-protocol was used among the NTLM protocols.&lt;/p&gt;&lt;p&gt;	- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.&lt;/span&gt;</description><pubDate>Tue, 07 Jun 2011 10:50:57 GMT</pubDate><dc:creator>RCThompson</dc:creator></item><item><title>Event ID 4625 and Code 0xc00002ee</title><link>http://forum.ultimatewindowssecurity.com/Topic538-168-1.aspx</link><description>Hi, I got event ID 4624 with Code 0xc00002ee (infrastructure: 2 DC's both Windows Server 2008). Can you tell me, what 0xc00002ee mean?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Alex</description><pubDate>Mon, 22 Nov 2010 05:53:17 GMT</pubDate><dc:creator>alex.fischer</dc:creator></item><item><title>Event ID 4625 Not Being Logged For Failed RDP Attempts</title><link>http://forum.ultimatewindowssecurity.com/Topic464-168-1.aspx</link><description>I am looking to audit failed RDP login attempts on the servers in my domain. When a login fails, I see an event logged in the Security Log on the domain controller (Event ID 4771), but there is no corresponding failure event logged in the Security Log on the server I am trying to RDP to. Shouldn't I see a 4625 event with a LogonType of 10?&lt;P&gt;(Note: Failed interactive logins (Type =2) are being logged correctly for workstation logins, both locally and to the domain, as are workstation unlocks (Type =7).) &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Configuration:&lt;/P&gt;&lt;P&gt;- Windows 2008 domain controller (mixed-mode)&lt;BR&gt;- Server trying to RDP to: Windows 2008&lt;BR&gt;- Workstation attempting from: Windows 7</description><pubDate>Wed, 08 Sep 2010 11:36:31 GMT</pubDate><dc:creator>awf</dc:creator></item><item><title>Non Descriptive field for Failure Reason in Win2008</title><link>http://forum.ultimatewindowssecurity.com/Topic87-168-1.aspx</link><description>Hi,&lt;br&gt;&lt;br&gt;As per the documentation on your website, the failure reason for 4625 event should be a descriptive field. Where as in the event log on Windows 2008 server, I could see the value like this , FailureReason = "%%2309", just wondering how do Interpret this binary to description ? &lt;br&gt;&lt;br&gt;And also I have similar problem with 4656 event, where the "ACCESSES" were descriptive in documentation where as the event log shows its binary value like "%%1553" &lt;br&gt;&lt;br&gt;Could you pls. clarify this for us ??? &lt;br&gt;&lt;br&gt;thx&lt;br&gt;Srinivas Chamarthi&lt;br&gt;&lt;br&gt;</description><pubDate>Sun, 03 May 2009 13:57:24 GMT</pubDate><dc:creator>chamarts</dc:creator></item><item><title>Failure information for old 534.</title><link>http://forum.ultimatewindowssecurity.com/Topic308-168-1.aspx</link><description>Hi I am looking for the Status and Sub Status for failed logins similar to the old 534 messages:  534: Logon Failure - The user has not been granted the requested logon type at this machine.  Has anyone come across this yet?  I am assuming they would come under 4625?&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Mark</description><pubDate>Tue, 16 Feb 2010 10:24:17 GMT</pubDate><dc:creator>mdstevens</dc:creator></item><item><title>Fails with Status: 0xc00000bb</title><link>http://forum.ultimatewindowssecurity.com/Topic78-168-1.aspx</link><description>Hi,&lt;/P&gt;&lt;P&gt;Thanx for valuable info in your post. However I managed to get this problem with a for me unkown Status value: 0xc00000bb.&lt;/P&gt;&lt;P&gt;Here's some info from the eventlog, maybe you can guide me further.&lt;/P&gt;&lt;P&gt;Account For Which Logon Failed:&lt;BR&gt; Security ID:  NULL SID&lt;BR&gt; Account Name:  &lt;A href="mailto:administrator@pbslab2.local"&gt;administrator@pbslab2.local&lt;/A&gt;&lt;BR&gt; Account Domain:  &lt;/P&gt;&lt;P&gt;Failure Information:&lt;BR&gt; Failure Reason:  An Error occured during Logon.&lt;BR&gt; Status:   0xc00000bb&lt;BR&gt; Sub Status:  0x0&lt;BR&gt;&lt;/P&gt;&lt;P&gt;My environment is as follows:&lt;/P&gt;&lt;P&gt;Windows Server 2003 as Domain Controller&lt;BR&gt;Windows Server 2008 running root CA (active directory certificate services)&lt;/P&gt;&lt;P&gt;I managed to issue a smart card user certificate for the domain administrator and store it on a Gemalto .NET v2+ smart card. When trying to logon to the ws2008 as domain adminstrator I get the error mentioned above.&lt;/P&gt;&lt;P&gt;I read here&lt;BR&gt;&lt;A href="http://msmvps.com/blogs/sp/archive/2007/06/02/smart-card-logon-error-0xc00000bb.aspx"&gt;http://msmvps.com/blogs/sp/archive/2007/06/02/smart-card-logon-error-0xc00000bb.aspx&lt;/A&gt;&lt;BR&gt;that it could be a missing certificate on the AD but I do have it.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;/Håkan Eriksson</description><pubDate>Fri, 24 Apr 2009 04:00:22 GMT</pubDate><dc:creator>Eriksson</dc:creator></item></channel></rss>
