Event Log entries?

K

Kevin

This is a lengthy post... Sorry but need to describe....

We have a server that we setup to capture every event in
the event log. We are noticing a strange group of entries
that we are not sure what it is. I assume it is some
standard OS / Network level entry because it happens often
and is a consistent set of entries but we do not know what
the entries mean and would like to know if anyone out
there does.

Log Entries....
Success audit
Category: Privilege use
Event ID: 576
Username: domain\computername$

In the Description:
Special Privileges assigned to new user
User Name and Domain Blank
Assigned: SeChangeNotifyPrivilege

Success audit
Category: Logon/Logoff
Event ID: 540
Username: domain\computername$

In the Description:
Successful Network logon
User Name: computername$
Domain: domain
Logon Type: 3

Success audit
Category: Logon/Logoff
Event ID: 538
Username: domain\computername$

In the Description:
User Logoff
User Name: computername$
Domain: domain
Logon Type: 3

These 3 entries always accompany each other. The
interesting issue is that this happened to one of our
servers over the weekend but that the entries were taking
place every second and filled up our 25mb log file in
about 5 hours. We disconnected the computer from the
network that was mentioned in the username field and these
entries stopped. We plugged the computer back in this
morning and it isn't happening?

We have done the normal virus / hack research but this
does not appear to be that at all. In fact we see in the
logs where other entries of this type are in the system
but for different computers....

We did notice that the Computer Browser service was on for
this server and it shouldn't have been so we turned it off.

Does anyone know what this is?

Kevin
 
B

Bobby McMillan [MSFT]

INLINE:

Pleae note that there are some products that cause excessive 538's 540's
and 576's ... What products are on the server that was pusing these every
second for 5 hours...

--------------------
| From: "Kevin" <[email protected]>
| Sender: "Kevin" <[email protected]>
| Subject: Event Log entries?
| Date: Tue, 30 Dec 2003 11:06:03 -0800

|
| This is a lengthy post... Sorry but need to describe....
|
| We have a server that we setup to capture every event in
| the event log. We are noticing a strange group of entries
| that we are not sure what it is. I assume it is some
| standard OS / Network level entry because it happens often
| and is a consistent set of entries but we do not know what
| the entries mean and would like to know if anyone out
| there does.
|
| Log Entries....
| Success audit
| Category: Privilege use
| Event ID: 576
| Username: domain\computername$
|
| In the Description:
| Special Privileges assigned to new user
| User Name and Domain Blank
| Assigned: SeChangeNotifyPrivilege


|
| Success audit
| Category: Logon/Logoff
| Event ID: 540
| Username: domain\computername$
|
| In the Description:
| Successful Network logon
| User Name: computername$
| Domain: domain
| Logon Type: 3


|
| Success audit
| Category: Logon/Logoff
| Event ID: 538
| Username: domain\computername$
|
| In the Description:
| User Logoff
| User Name: computername$
| Domain: domain
| Logon Type: 3
|
| These 3 entries always accompany each other. The
| interesting issue is that this happened to one of our
| servers over the weekend but that the entries were taking
| place every second and filled up our 25mb log file in
| about 5 hours. We disconnected the computer from the
| network that was mentioned in the username field and these
| entries stopped. We plugged the computer back in this
| morning and it isn't happening?
|
| We have done the normal virus / hack research but this
| does not appear to be that at all. In fact we see in the
| logs where other entries of this type are in the system
| but for different computers....
|
| We did notice that the Computer Browser service was on for
| this server and it shouldn't have been so we turned it off.
|
| Does anyone know what this is?
|
| Kevin
|
|
|

This posting is provided "AS IS" with no warranties, and confers no rights.
 
G

Guest

The server is a W2K web server with OWA 5.5. Fairly
vanilla...

The workstation that was identified in the event log
is a laptop with W2K, OfficeXP pro, VB6 Ent, IIS5,
VS.Net2K3, Zone Alarm Pro, and several other programs.
This laptop has been on the network for 2+ years and this
fit has not occured since (or before) the occurance
outlined below.

Thanks
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top