Help decipher this event log

Discussion in 'other security issues & news' started by lunarlander, Oct 15, 2011.

Thread Status:
Not open for further replies.
  1. lunarlander

    lunarlander Registered Member

    Apr 30, 2011
    Hi Everyone,

    I get the following event and can't understand what it is saying:

    An account failed to log on.

    Security ID: Karen-PC\Karen
    Account Name: Karen
    Account Domain: Karen-PC
    Logon ID: 0x64be4

    Logon Type: 3

    Account For Which Logon Failed:
    Security ID: NULL SID
    Account Name: Guest
    Account Domain: KO-PC

    Failure Information:
    Failure Reason: Account currently disabled.
    Status: 0xc000006e
    Sub Status: 0xc0000072

    Process Information:
    Caller Process ID: 0xd54
    Caller Process Name: C:\Windows\explorer.exe

    Network Information:
    Workstation Name: Karen-PC
    Source Network Address: -
    Source Port: -

    Detailed Authentication Information:
    Logon Process: Advapi
    Authentication Package: Negotiate
    Transited Services: -
    Package Name (NTLM only): -
    Key Length: 0

    This event is generated when a logon request fails. It is generated on the
    computer where access was attempted.

    The Subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

    The Logon Type field indicates the kind of logon that was requested. The most common types are 2 (interactive) and 3 (network).

    The Process Information fields indicate which account and process on the system requested the logon.

    The Network Information fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in
    some cases.

    The authentication information fields provide detailed information about this
    specific logon request.
    - Transited services indicate which intermediate services have participated in this logon request.
    - Package name indicates which sub-protocol was used among the NTLM protocols.
    - Key length indicates the length of the generated session key. This
    will be 0 if no session key was requested.


    The part which I don't undestand is that the 'subject' is Karen ( the admin account ) . Is the log saying that Karen attempted to login as Guest ? Or does the event mean that someone tried to login as Guest while Karen is logged on? Also, the logon type was 3, which should mean someone tried to logon thru the network. The system is running Vista Business.
  2. siljaline

    siljaline Registered Member

    Jun 29, 2003
    Perhaps a better bet would be to ask a Microsoft Operating System Engineer.

    You may do so via Microsoft Answers. There is no charge to use this service.

    Best of luck to you.
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.