What just happened?
From: Troy Murray (troymurray@hotmail.com)
Date: 08/31/02
- Next message: Charlie Tame: "Re: 2 files titled Systray.exe? Worm maybe?"
- Previous message: Eric Perlin [MS]: "Re: Automatically log off user in Win 2000"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "Troy Murray" <troymurray@hotmail.com> Date: Fri, 30 Aug 2002 23:27:27 -0400
OK, I was logged into my server using the Terminal Services when suddenly I
got kicked out. I tried to log back in but wasn't able to with my account
so I used the Administrator account. I then found this in the Event Log:
Event Type: Success Audit
Event Source: Security
Event Category: Account Management
Event ID: 630
Date: 8/30/2002
Time: 10:03:40 PM
User: NT AUTHORITY\SYSTEM
Computer: TE-ADMIN
Description:
User Account Deleted:
Target Account Name: tmurray
Target Domain: TE-ADMIN
Target Account ID: S-1-5-21-682003330-1957994488-1202660629-1004
Caller User Name: TE-ADMIN$
Caller Domain: ED_DOMAIN
Caller Logon ID: (0x0,0x3E7)
Privileges: -
Did the computer delete me or is someone else using the computer account to
do this?
- Next message: Charlie Tame: "Re: 2 files titled Systray.exe? Worm maybe?"
- Previous message: Eric Perlin [MS]: "Re: Automatically log off user in Win 2000"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|