PC Review


Reply
Thread Tools Rating: Thread Rating: 1 votes, 1.00 average.

Defender Scans Network Drives Which Are Not Mapped

 
 
=?Utf-8?B?bG9yYVhYYXJvbA==?=
Guest
Posts: n/a
 
      14th Nov 2006
I have installed the full release version of Windows Defender. When I
perform a full system scan, whether manually or automatically, Windows
Defender attempts to scan network resources which are not mapped.

What is really strange is that these attempts are not made on any of the
machines on the LAN where my Active Directory Domain resides. These
authentication failures occur in a Windows environment in a separate
building, which is connected by an IPSec VPN, allowing traffic from my office
to that building to be instantiated.

The failures are logged because Defender is running as my local machine,
which has no privileges in the other environment. There are always two
errors in quick succession because I've enabled Account Logon and
Logon/Logoff failure auditing, which follow:

======================================================
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 11/14/2006
Time: 1:41:01 AM
User: NT AUTHORITY\SYSTEM
Computer: T#####
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: L####$
Source Workstation: L####
Error Code: 0xC0000064
======================================================
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 11/14/2006
Time: 1:41:01 AM
User: NT AUTHORITY\SYSTEM
Computer: T#####
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: L####$
Domain: C#########
Logon Type: 3
Logon Process: NtLmSsp
Authentication Package: NTLM
Workstation Name: L####
Caller User Name: -
Caller Domain: -
Caller Logon ID: -
Caller Process ID: -
Transited Services: -
Source Network Address: 192.#.#.#
Source Port: 0
======================================================

I need a way to turn this off in Windows Defender.

1> the drives on these machines are not mapped, so I'm not sure where
Defender is even getting the machine names (unless it's pulling it from my
explorer history or something).

2> these machines are not even in a trust relationship with my domain.

3> there is not a list of "items to scan" anywhere that I can find, in the
registry, flat files, or online. There is the list of "Do not scan these
files or folders," but that's exclusive - I need the inclusive.

4> where is the promised .adm file which was supposed to accompany the full
release?

As a domain administrator, I am going to be hard pressed to deploy this
corporate-wide if I can't configure it to not scan network devices which are
not mapped, and have to run around trying to block it everywhere to prevent
it from attempting authentication in other connected environments.

Thanks for your help, anyone.

- Eric McWhorter
 
Reply With Quote
 
 
 
 
=?Utf-8?B?bG9yYVhYYXJvbA==?=
Guest
Posts: n/a
 
      14th Nov 2006
..adm file is in the proper location (C:\WINDOWS\inf) - my apologies for
having overlooked it.

- Eric McWhorter

"loraXXarol" wrote:

> I have installed the full release version of Windows Defender. When I
> perform a full system scan, whether manually or automatically, Windows
> Defender attempts to scan network resources which are not mapped.
>
> What is really strange is that these attempts are not made on any of the
> machines on the LAN where my Active Directory Domain resides. These
> authentication failures occur in a Windows environment in a separate
> building, which is connected by an IPSec VPN, allowing traffic from my office
> to that building to be instantiated.
>
> The failures are logged because Defender is running as my local machine,
> which has no privileges in the other environment. There are always two
> errors in quick succession because I've enabled Account Logon and
> Logon/Logoff failure auditing, which follow:
>
> ======================================================
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 680
> Date: 11/14/2006
> Time: 1:41:01 AM
> User: NT AUTHORITY\SYSTEM
> Computer: T#####
> Description:
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: L####$
> Source Workstation: L####
> Error Code: 0xC0000064
> ======================================================
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 529
> Date: 11/14/2006
> Time: 1:41:01 AM
> User: NT AUTHORITY\SYSTEM
> Computer: T#####
> Description:
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: L####$
> Domain: C#########
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name: L####
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: 192.#.#.#
> Source Port: 0
> ======================================================
>
> I need a way to turn this off in Windows Defender.
>
> 1> the drives on these machines are not mapped, so I'm not sure where
> Defender is even getting the machine names (unless it's pulling it from my
> explorer history or something).
>
> 2> these machines are not even in a trust relationship with my domain.
>
> 3> there is not a list of "items to scan" anywhere that I can find, in the
> registry, flat files, or online. There is the list of "Do not scan these
> files or folders," but that's exclusive - I need the inclusive.
>
> 4> where is the promised .adm file which was supposed to accompany the full
> release?
>
> As a domain administrator, I am going to be hard pressed to deploy this
> corporate-wide if I can't configure it to not scan network devices which are
> not mapped, and have to run around trying to block it everywhere to prevent
> it from attempting authentication in other connected environments.
>
> Thanks for your help, anyone.
>
> - Eric McWhorter

 
Reply With Quote
 
=?Utf-8?B?RW5nZWw=?=
Guest
Posts: n/a
 
      14th Nov 2006
Hello Eric,

Try this, exclude the entire networked drive from scanning under WD Advanced
Options.
--

"loraXXarol" wrote:

> I have installed the full release version of Windows Defender. When I
> perform a full system scan, whether manually or automatically, Windows
> Defender attempts to scan network resources which are not mapped.
>
> What is really strange is that these attempts are not made on any of the
> machines on the LAN where my Active Directory Domain resides. These
> authentication failures occur in a Windows environment in a separate
> building, which is connected by an IPSec VPN, allowing traffic from my office
> to that building to be instantiated.
>
> The failures are logged because Defender is running as my local machine,
> which has no privileges in the other environment. There are always two
> errors in quick succession because I've enabled Account Logon and
> Logon/Logoff failure auditing, which follow:
>
> ======================================================
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Account Logon
> Event ID: 680
> Date: 11/14/2006
> Time: 1:41:01 AM
> User: NT AUTHORITY\SYSTEM
> Computer: T#####
> Description:
> Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> Logon account: L####$
> Source Workstation: L####
> Error Code: 0xC0000064
> ======================================================
> Event Type: Failure Audit
> Event Source: Security
> Event Category: Logon/Logoff
> Event ID: 529
> Date: 11/14/2006
> Time: 1:41:01 AM
> User: NT AUTHORITY\SYSTEM
> Computer: T#####
> Description:
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: L####$
> Domain: C#########
> Logon Type: 3
> Logon Process: NtLmSsp
> Authentication Package: NTLM
> Workstation Name: L####
> Caller User Name: -
> Caller Domain: -
> Caller Logon ID: -
> Caller Process ID: -
> Transited Services: -
> Source Network Address: 192.#.#.#
> Source Port: 0
> ======================================================
>
> I need a way to turn this off in Windows Defender.
>
> 1> the drives on these machines are not mapped, so I'm not sure where
> Defender is even getting the machine names (unless it's pulling it from my
> explorer history or something).
>
> 2> these machines are not even in a trust relationship with my domain.
>
> 3> there is not a list of "items to scan" anywhere that I can find, in the
> registry, flat files, or online. There is the list of "Do not scan these
> files or folders," but that's exclusive - I need the inclusive.
>
> 4> where is the promised .adm file which was supposed to accompany the full
> release?
>
> As a domain administrator, I am going to be hard pressed to deploy this
> corporate-wide if I can't configure it to not scan network devices which are
> not mapped, and have to run around trying to block it everywhere to prevent
> it from attempting authentication in other connected environments.
>
> Thanks for your help, anyone.
>
> - Eric McWhorter

 
Reply With Quote
 
=?Utf-8?B?bG9yYVhYYXJvbA==?=
Guest
Posts: n/a
 
      14th Nov 2006
Hi, Engel -

Thanks for your response! I'm not quite sure I understand your suggestion.
Are you saying I should add the machines in the external environment to the
list of "do not scan these files or locations?" I'd really rather not have
to do this for every install I do. What I'm looking for is the setting which
tells Defender to INCLUDE network locations to begin with - it seems
counterintuitive to have this action without a way to shut it off.

Keep in mind that a> I do not see these authentication attempts on my LAN,
just at this remote location, and b> the machines against which my machine
tries to authenticate are not mapped as network drives. Most of them don't
even have anything but the default administrator shares enabled. Certainly,
they don't show up under the "browse for folder" dialog when I attempt to add
them to the list, and they don't show up in the "disconnect network drives"
dialog either.

Without a priori knowledge of what was being accessed, I can't add anything
to the list in "do not scan these files or locations" anyway - unless I add
EVERYTHING from each of several servers - tedious and not the expected way of
having to do this.

This is why I was wondering if there existed a log of devices/drives that
Defender has ATTEMPTED to contact for a scan. This way, I could identify the
network locations to block.

Thanks for your help!

- Eric McWhorter

"Engel" wrote:

> Hello Eric,
>
> Try this, exclude the entire networked drive from scanning under WD Advanced
> Options.
> --
>
> "loraXXarol" wrote:
>
> > I have installed the full release version of Windows Defender. When I
> > perform a full system scan, whether manually or automatically, Windows
> > Defender attempts to scan network resources which are not mapped.
> >
> > What is really strange is that these attempts are not made on any of the
> > machines on the LAN where my Active Directory Domain resides. These
> > authentication failures occur in a Windows environment in a separate
> > building, which is connected by an IPSec VPN, allowing traffic from my office
> > to that building to be instantiated.
> >
> > The failures are logged because Defender is running as my local machine,
> > which has no privileges in the other environment. There are always two
> > errors in quick succession because I've enabled Account Logon and
> > Logon/Logoff failure auditing, which follow:
> >
> > ======================================================
> > Event Type: Failure Audit
> > Event Source: Security
> > Event Category: Account Logon
> > Event ID: 680
> > Date: 11/14/2006
> > Time: 1:41:01 AM
> > User: NT AUTHORITY\SYSTEM
> > Computer: T#####
> > Description:
> > Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
> > Logon account: L####$
> > Source Workstation: L####
> > Error Code: 0xC0000064
> > ======================================================
> > Event Type: Failure Audit
> > Event Source: Security
> > Event Category: Logon/Logoff
> > Event ID: 529
> > Date: 11/14/2006
> > Time: 1:41:01 AM
> > User: NT AUTHORITY\SYSTEM
> > Computer: T#####
> > Description:
> > Logon Failure:
> > Reason: Unknown user name or bad password
> > User Name: L####$
> > Domain: C#########
> > Logon Type: 3
> > Logon Process: NtLmSsp
> > Authentication Package: NTLM
> > Workstation Name: L####
> > Caller User Name: -
> > Caller Domain: -
> > Caller Logon ID: -
> > Caller Process ID: -
> > Transited Services: -
> > Source Network Address: 192.#.#.#
> > Source Port: 0
> > ======================================================
> >
> > I need a way to turn this off in Windows Defender.
> >
> > 1> the drives on these machines are not mapped, so I'm not sure where
> > Defender is even getting the machine names (unless it's pulling it from my
> > explorer history or something).
> >
> > 2> these machines are not even in a trust relationship with my domain.
> >
> > 3> there is not a list of "items to scan" anywhere that I can find, in the
> > registry, flat files, or online. There is the list of "Do not scan these
> > files or folders," but that's exclusive - I need the inclusive.
> >
> > 4> where is the promised .adm file which was supposed to accompany the full
> > release?
> >
> > As a domain administrator, I am going to be hard pressed to deploy this
> > corporate-wide if I can't configure it to not scan network devices which are
> > not mapped, and have to run around trying to block it everywhere to prevent
> > it from attempting authentication in other connected environments.
> >
> > Thanks for your help, anyone.
> >
> > - Eric McWhorter

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Conflict between USB Drives and mapped network drives. Joao Windows XP Help 3 27th Nov 2007 07:24 PM
WD scans network drives, any way to disable? Joe_M Spyware Discussion 2 27th May 2006 02:33 AM
Drive Letter clash (mapped network drives vs physical drives) =?Utf-8?B?T2xpdmVyIFdoaXRlbWFu?= Windows XP General 4 4th Aug 2005 09:59 AM
Enumerate all the drives including Mapped network drives on a serv =?Utf-8?B?UHJhZGVlcCBTdW5kYXJhbShNU0ZUKQ==?= Microsoft ASP .NET 2 26th Feb 2005 03:13 PM
Mapped Network Drives, USB Hard drives and "Not enough server storage is available to process this command" CWatters Windows XP General 2 11th Nov 2003 07:09 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:03 AM.