﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 540 - Successful Network Logon  / Unexplained 540 events on W2K workstation in a domain / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Tue, 07 Feb 2012 12:15:58 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>i think you will need to enable Windows Firewall auditing and trace incoming port connections</description><pubDate>Tue, 13 Oct 2009 21:31:13 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>RE: Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>This workstation is not hosting IIS.  The only shares are default ones: Admin$, C$, IPC$, and print$&lt;/P&gt;&lt;P&gt;Here are the services:&lt;/P&gt;&lt;P&gt;Name                                                Status    Startup TypeLog On As&lt;BR&gt;Alerter                                             Started   Automatic   LocalSystem&lt;BR&gt;Application Management                                        Manual      LocalSystem&lt;BR&gt;Automatic Updates                                             Disabled    LocalSystem&lt;BR&gt;Background Intelligent Transfer Service                       Manual      LocalSystem&lt;BR&gt;ClipBook                                                      Manual      LocalSystem&lt;BR&gt;COM+ Event System                                   Started   Manual      LocalSystem&lt;BR&gt;Computer Browser                                              Disabled    LocalSystem&lt;BR&gt;DHCP Client                                         Started   Automatic   LocalSystem&lt;BR&gt;Distributed Link Tracking Client                              Disabled    LocalSystem&lt;BR&gt;Distributed Transaction Coordinator                           Manual      LocalSystem&lt;BR&gt;DNS Client                                          Started   Automatic   LocalSystem&lt;BR&gt;Event Log                                           Started   Automatic   LocalSystem&lt;BR&gt;Fax Service                                                   Manual      LocalSystem&lt;BR&gt;Indexing Service                                              Manual      LocalSystem&lt;BR&gt;InstallDriver Table Manager                                   Manual      LocalSystem&lt;BR&gt;Internet Connection Sharing                                   Manual      LocalSystem&lt;BR&gt;IPSEC Policy Agent                                  Started   Automatic   LocalSystem&lt;BR&gt;Logical Disk Manager                                Started   Automatic   LocalSystem&lt;BR&gt;Logical Disk Manager Administrative Service                   Manual      LocalSystem&lt;BR&gt;Messenger                                                     Disabled    LocalSystem&lt;BR&gt;Net Logon                                           Started   Automatic   LocalSystem&lt;BR&gt;NetMeeting Remote Desktop Sharing                             Manual      LocalSystem&lt;BR&gt;Network Connections                                 Started   Manual      LocalSystem&lt;BR&gt;Network DDE                                                   Manual      LocalSystem&lt;BR&gt;Network DDE DSDM                                              Manual      LocalSystem&lt;BR&gt;NT LM Security Support Provider                               Manual      LocalSystem&lt;BR&gt;Performance Logs and Alerts                                   Manual      LocalSystem&lt;BR&gt;Plug and Play                                       Started   Automatic   LocalSystem&lt;BR&gt;Print Spooler                                       Started   Automatic   LocalSystem&lt;BR&gt;Protected Storage                                   Started   Automatic   LocalSystem&lt;BR&gt;QoS RSVP                                                      Manual      LocalSystem&lt;BR&gt;Remote Access Auto Connection Manager                         Manual      LocalSystem&lt;BR&gt;Remote Access Connection Manager                    Started   Manual      LocalSystem&lt;BR&gt;Remote Procedure Call (RPC)                         Started   Automatic   LocalSystem&lt;BR&gt;Remote Procedure Call (RPC) Locator                 Started   Automatic   LocalSystem&lt;BR&gt;Remote Registry Service                             Started   Automatic   LocalSystem&lt;BR&gt;Removable Storage                                   Started   Automatic   LocalSystem&lt;BR&gt;Routing and Remote Access                                     Disabled    LocalSystem&lt;BR&gt;RunAs Service                                       Started   Automatic   LocalSystem&lt;BR&gt;SavRoam                                             Started   Automatic   LocalSystem&lt;BR&gt;Security Accounts Manager                           Started   Automatic   LocalSystem&lt;BR&gt;Server                                              Started   Automatic   LocalSystem&lt;BR&gt;Smart Card                                                    Manual      LocalSystem&lt;BR&gt;Smart Card Helper                                             Manual      LocalSystem&lt;BR&gt;Symantec AntiVirus                                  Started   Automatic   LocalSystem&lt;BR&gt;Symantec AntiVirus Definition Watcher               Started   Automatic   LocalSystem&lt;BR&gt;Symantec Event Manager                              Started   Automatic   LocalSystem&lt;BR&gt;Symantec Network Drivers Service                    Started   Automatic   LocalSystem&lt;BR&gt;Symantec Password Validation                                  Manual      LocalSystem&lt;BR&gt;Symantec Settings Manager                           Started   Automatic   LocalSystem&lt;BR&gt;Symantec SPBBCSvc                                             Manual      LocalSystem&lt;BR&gt;System Event Notification                           Started   Automatic   LocalSystem&lt;BR&gt;Task Scheduler                                      Started   Automatic   LocalSystem&lt;BR&gt;TCP/IP NetBIOS Helper Service                       Started   Automatic   LocalSystem&lt;BR&gt;Telephony                                           Started   Manual      LocalSystem&lt;BR&gt;Telnet                                                        Disabled    LocalSystem&lt;BR&gt;Uninterruptible Power Supply                                  Manual      LocalSystem&lt;BR&gt;Utility Manager                                               Manual      LocalSystem&lt;BR&gt;VNC Server Version 4                                Started   Automatic   LocalSystem&lt;BR&gt;Windows Installer                                             Manual      LocalSystem&lt;BR&gt;Windows Management Instrumentation                  Started   Automatic   LocalSystem&lt;BR&gt;Windows Management Instrumentation Driver ExtensionsStarted   Manual      LocalSystem&lt;BR&gt;Windows Time                                        Started   Automatic   LocalSystem&lt;BR&gt;Wireless Configuration                                        Manual      LocalSystem&lt;BR&gt;Workstation                                         Started   Automatic   LocalSystem&lt;BR&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time!</description><pubDate>Tue, 13 Oct 2009 16:28:49 GMT</pubDate><dc:creator>kr_lly</dc:creator></item><item><title>RE: Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>There are a lot of things that could be causing it.  Is the user of this workstation hosting an IIS site?  Are users browsing the network and enumerating the computer's shared folders?  What services are running on the this computer? - Server Service?  IIS?</description><pubDate>Tue, 13 Oct 2009 13:18:19 GMT</pubDate><dc:creator>RandyFranklinSmith</dc:creator></item><item><title>Unexplained 540 events on W2K workstation in a domain</title><link>http://forum.ultimatewindowssecurity.com/Topic232-34-1.aspx</link><description>Does anyone have an explanation for this sequence of three Events on a W2K workstation that's in a domain? The workstation name is WK3577. The user in this case (AM\User1) is a valid domain user but there is no logical connection between them and this workstation.  The are multiple user accounts generating these Events.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Privilege Use &lt;BR&gt;Event ID: 576&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Special privileges assigned to new logon:&lt;BR&gt;  User Name: &lt;BR&gt;  Domain:  &lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Assigned:  SeChangeNotifyPrivilege &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 540&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:09 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;Successful Network Logon:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt;  Logon Process: Kerberos&lt;BR&gt;  Authentication Package: Kerberos&lt;BR&gt;  Workstation Name:  &lt;/P&gt;&lt;P&gt;&lt;BR&gt;Event Type: Success Audit&lt;BR&gt;Event Source: Security&lt;BR&gt;Event Category: Logon/Logoff &lt;BR&gt;Event ID: 538&lt;BR&gt;Date:  10/11/2009&lt;BR&gt;Time:  11:47:21 PM&lt;BR&gt;User:  AM\User1&lt;BR&gt;Computer: WK3577&lt;BR&gt;Description:&lt;BR&gt;User Logoff:&lt;BR&gt;  User Name: User1&lt;BR&gt;  Domain:  AM&lt;BR&gt;  Logon ID:  (0x0,0x564620)&lt;BR&gt;  Logon Type: 3&lt;BR&gt; </description><pubDate>Mon, 12 Oct 2009 13:23:35 GMT</pubDate><dc:creator>kr_lly</dc:creator></item></channel></rss>
