Forums  Register  Login  My Profile  Inbox  Address Book  My Subscription  My Forums 

Member List  Search  FAQ  Ticket List  Log Out

 

Help with Event ID 4625

 
Logged in as: Guest
Users viewing this topic: none
  Printable Version
All Forums >> [Networking & Security] >> GFI EventsManager >> Help with Event ID 4625 Page: [1]
Login
Message << Older Topic   Newer Topic >>
Help with Event ID 4625 - 7.Apr.2009 11:26:26 AM   
b.nault

 

Posts: 1
Score: 0
Joined: 7.Apr.2009
Status: offline
Hi,
I keep getting a warning about an unknown username or password - Event ID 4625.  However, the user says he is not trying to login at the time, and it is not showing me the IP address.


This is what I get:

Network Information:

      Workstation Name: HPDV6575-01

      Source Network Address: fe80::1fb:87af:4864:d6a8

      Source Port:            49173

Anyone have any tips on how I can trace this and find out exactly what is going on?

Thanks!

_____________________________

~Bradly
Post #: 1
RE: Help with Event ID 4625 - 10.Apr.2009 8:11:14 AM   
mfhjek0

 

Posts: 24
Score: 0
Joined: 14.Jun.2006
Status: offline
quote:

4625
In Windows "logon" events are not simply someone entering their id and password.  There are any number of actions that Window's bundles under a "logon event".  Any resource (mapped drive, e-mail, printer, etc) the user has connected to, periodically triggers authentication which falls under "logon" events.  Services could have been setup to use that account id and password to run and scheduled jobs may also be kicking off using that id and pw, all may look like logons depending on the action.

I usually start tracking at that workstation and look at it's security event log, also are any services setup to run on that machine using that person's account, any scheduled jobs using the account?  Does the user logoff at the end of the day and is the event occuring during work hours or after?  Did the user recently change their password and that is when the errors started?

If the password was recently changed then it is probably a process trying to re-authenticate or verify credentials with the old password.  Make sure the person logs off from all their machines and logs back on with the new password.  Many people do not logoff, they lock their account or disconnect. 

good luck


(in reply to b.nault)
Post #: 2
Page:   [1]
All Forums >> [Networking & Security] >> GFI EventsManager >> Help with Event ID 4625 Page: [1]
Jump to:





New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts