V Green said:
Paste the last several Security Event Descriptions into Notepad and
then paste that text here so we can look at it.
I copied a few from 12/25, and a few more from 1/5, just to get a range of
events. These are Security events only. I will go get the others after
this:
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 551
Date: 12/25/2006
Time: 9:48:53 PM
User: LENOVO-549F05D8\Diane
Computer: LENOVO-549F05D8
Description:
User initiated logoff:
User Name: Diane
Domain: LENOVO-549F05D8
Logon ID: (0x0,0x12f6c)
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Policy Change
Event ID: 858
Date: 12/25/2006
Time: 9:49:17 PM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Windows Firewall group policy settings have been applied.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Policy Change
Event ID: 615
Date: 12/25/2006
Time: 9:49:17 PM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LENOVO-549F05D8
Description:
IPSec Services: IPSec Services failed to get the complete list of network
interfaces on the machine. This can be a potential security hazard to the
machine since some of the network interfaces may not get the protection as
desired by the applied IPSec filters. Please run IPSec monitor snap-in to
further diagnose the problem.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: System Event
Event ID: 513
Date: 12/25/2006
Time: 9:49:19 PM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Windows is shutting down. All logon sessions will be terminated by this
shutdown.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: System Event
Event ID: 514
Date: 12/26/2006
Time: 1:16:40 PM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
An authentication package has been loaded by the Local Security Authority.
This authentication package will be used to authenticate logon attempts.
Authentication Package Name: C:\WINDOWS\system32\LSASRV.dll : Negotiate
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: System Event
Event ID: 514
Date: 12/26/2006
Time: 1:16:40 PM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
An authentication package has been loaded by the Local Security Authority.
This authentication package will be used to authenticate logon attempts.
Authentication Package Name: C:\WINDOWS\system32\kerberos.dll : Kerberos
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
END OF 12/25 SECURITY EVENTS
:::::::::::::::::::::::::::::::::::::::::::::::::::
BEGINNING OF 1/05 SECURITY EVENTS
Event Type: Success Audit
Event Source: Security
Event Category: Policy Change
Event ID: 850
Date: 1/5/2007
Time: 11:05:39 AM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
A port was listed as an exception when the Windows Firewall started.
Policy origin: Local Policy
Profile used: -
Interface: -
Name: -
Port number: 16946
Protocol: UDP
State: Enabled
Scope: All subnets
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Policy Change
Event ID: 858
Date: 1/5/2007
Time: 11:05:39 AM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Windows Firewall group policy settings have been applied.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Policy Change
Event ID: 858
Date: 1/5/2007
Time: 11:05:39 AM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Windows Firewall group policy settings have been applied.
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 528
Date: 1/5/2007
Time: 11:05:45 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LENOVO-549F05D8
Description:
Successful Logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Logon Type: 5
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name:
Logon GUID: -
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Success Audit
Event Source: Security
Event Category: Privilege Use
Event ID: 576
Date: 1/5/2007
Time: 11:05:45 AM
User: NT AUTHORITY\NETWORK SERVICE
Computer: LENOVO-549F05D8
Description:
Special privileges assigned to new logon:
User Name: NETWORK SERVICE
Domain: NT AUTHORITY
Logon ID: (0x0,0x3E4)
Privileges: SeAuditPrivilege
SeAssignPrimaryTokenPrivilege
SeChangeNotifyPrivilege
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/5/2007
Time: 11:06:23 AM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: Diane
Source Workstation: LENOVO-549F05D8
Error Code: 0xC000006E
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/5/2007
Time: 11:06:23 AM
User: NT AUTHORITY\SYSTEM
Computer: LENOVO-549F05D8
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: Diane
Domain: LENOVO-549F05D8
Logon Type: 8
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: LENOVO-549F05D8
For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.