NT AUTHORITY / ANONYMOUS LOGON

From: Curt (curt@rettke.org)
Date: 12/19/02


From: "Curt" <curt@rettke.org>
Date: Thu, 19 Dec 2002 00:35:42 -0800

I have Windows XP Home. I completely shutdown and the
restart my computer with with no network connections
(e.g. my DSL wireless modem card is unplugged). When I
look in the event viewer immeditely after this, there is
an event as follows:

======================================
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 540
Date: 12/19/2002
Time: 3:06:45 AM
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: CURT-TOSHIBA
Description:
Successful Network Logon:
         User Name:
         Domain:
         Logon ID: (0x0,0xEC1F)
         Logon Type: 3
         Logon Process: NtLmSsp
         Authentication Package: NTLM
         Workstation Name:
         Logon GUID: {00000000-0000-0000-0000-
000000000000}

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
================================

I have no idea where this anonymous logon is coming from.
Any ideas? Could it be some kind of process running on
my machine which is helping to a) log information such as
websites visited or b) enable a hacker to gain access to
my machine when I do connect it to the network?



Relevant Pages