Failed Logon Guest Account via Explorer.exe
windows server 2008 r2 -> domain machine local guest account. local security policy has guest disbaled, gpo has guest renamed not defined on disabled/enabled.
i'll focus on 1 machine, has occurred on several other machines. seeing logon failures in windows event logs associated our guest account. drilling these eventlogs, i've foudn local guest account, , calling process explorer.exe:
logname=security
sourcename=microsoft windows security auditing.
eventcode=4625
eventtype=0
type=information
computername=anonaserver.ncsgroup.bnsf.com
taskcategory=logon
opcode=info
recordnumber=397235473
keywords=audit failure
message=an account failed to log on.
subject:
security id: anonaserver\anonauser
account name: anonauser
account domain: anonaserver
logon id: 0x16f84c6
logon type: 3
account for which logon failed:
security id: null sid
account name: guest
account domain: anonaserver
failure information:
failure reason: account currently disabled.
status: 0xc000006e
sub status: 0xc0000072
process information:
caller process id: 0x1640
caller process name: c:\windows\explorer.exe
network information:
workstation name: anonaserver
source network address: -
source port: -
detailed authentication information:
logon process: advapi
authentication package: negotiate
transited services: -
package name (ntlm only): -
i've included entire output. i drilled machine, found person security id associated calling process. opened procexp64.exe, found pid, did bring front , says, windows explorer.exe. 1 had been opened "pictures" under users documents. said hadn't navigated windows explorer process yet (fellow admin, he accurate).
either way, doesn't seem rare of issue, having trouble nailing down exactely occurring , more important how put end it. gpo info: network access: sharing , security model local accounts: classic
accounts: guest account status: not defined
accounts: rename guest account: enabled , renamed
thanks
hi,
event, can read user anonauser trying logon network. please check whether rdp session. if not, recommend doing full safety scan on machine check if it's infected.
thanks, brian
please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread.
Windows Server > Group Policy
Comments
Post a Comment