RE: Help with delayed logoff entry



You might have a service running with alternate credentials. Which user is
triggering the event, and what is the login type?

Event ID 538

User Logoff:
User Name: Guest
Domain: MAGIC
Logon ID: (0x0,0x1EC7356E)
Logon Type: 3

Here are various login types:

2 is interactive
3 is network
4 is batch
5 is a service
7 is an unlock (of the screen saver)

There are more types, but you get the idea.

Vinson

"scott@xxxxxxx" wrote:

I have a Windows XP Pro system with Service Pack 2, connected to a
Samba server (if that makes any difference). Auditing on the Windows
machine is turned on, and the security logs show two accounts with
logoff times long after their login times. This machine is in an
isolated network.

I am the only person with admin rights.

What might cause Windows XP w/SP2 to record a delayed logoff? I
searched for any file creation/modification dates for the date/time of
the logoff entry, but there was no hit.

The first Event ID is 551, followed by 538.

I have reviewed all the audit logs I could find, but on the Windows
system and the samba server, but no correlations anywhere.

Insights are welcome. I don't believe the system was hacked - I
just need to find out why/how Windows reported logoffs long after the
user logged in (one person's entry was about 12 hours after the fact,
and another person's entry, on the same computer, was a few days
later).

Neither person said they had any jobs running, but maybe Windows did
behind the scenes...???

Thanks.

Scott

.



Relevant Pages

  • Re: Stopping Windows File Protection
    ... MS-MVP Windows Shell/User ... >> 4 In the right pane, double-click Verbose vs normal status messages. ... >> 6 Close Group Policy Object Editor, click OK, and then quit Active ... >> Logon / Logoff status messages setting is turned on. ...
    (microsoft.public.windowsxp.general)
  • Re: login/logoff Report
    ... On the client PC I do see the logoff script run in the logoff window. ... also run gpupdate /force on the server and client. ... Server 2003, Windows XP Professional, or Windows 2000 ... Make sure the "logging folder" share has Share Permissions: ...
    (microsoft.public.windows.server.sbs)
  • Track Domain User Logons and Logoffs
    ... with logon/logoff events for all users within our windows ... Message: Successful Network Logon: ... EventCode: 540 ... Message: User Logoff: ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Windows offline folders sync issue
    ... you can initiate using it using mobsync command in a script if required. ... The only way is to manual force it or logoff and login in ... Windows offline folders work very well except uunder the following condition. ... the cable for example gets disconnected or I lost connectivity then the Icon ...
    (microsoft.public.windowsxp.general)
  • Re: Problems with logging off after upgrade to 2003 SP2
    ... You mention that users are unable to logoff. ... How to enable user environment debug logging in retail builds of Windows ... How to enable verbose startup, shutdown, logon, and logoff status ...
    (microsoft.public.windows.terminal_services)