Strange Logon Process: Ðùº... comments?
- From: agustinchernitsky@xxxxxxxxxxxx
- Date: 10 Jul 2006 15:47:59 -0700
Hello Everyone!
I am getting failed logons in my exchange 2000 server running on
Win2k3. All latest SP applied. The event is as follows:
<<<<
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 537
Date: 7/10/2006
Time: 3:21:07 PM
User: NT AUTHORITY\SYSTEM
Computer: MAIL
Description:
Logon Failure:
Reason: An error occurred during logon
User Name:
Domain:
Logon Type: 3
Logon Process: Ðùº
Authentication Package: NTLM
Workstation Name:
Status code: 0x80090308
Substatus code: 0x0
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.168.100.10
Source Port: 40687
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
The IP 192.168.100.10 is an ISA 2004 server... no service pack.
Any ideas on whe the logon process is "Ðùº"??? I can't find any
strange processes or any strange services. I will run a rootkit
revealer, but I would love some comments on this!
Thanks!
Agustin.
.
- Prev by Date: Re: IIS prompting for password but integrated auth is only method
- Next by Date: Re: IIS prompting for password but integrated auth is only method
- Previous by thread: IIS prompting for password but integrated auth is only method
- Next by thread: Re: Utility to export file, folder, and share permissions
- Index(es):
Relevant Pages
|