none
Intrusion Attack? - understanding the Log. RRS feed

  • Question

  • Hi peeps,

    I have this log inside my Computer's Security event:

    Event Type:	Failure Audit
    Event Source:	Security
    Event Category:	Logon/Logoff 
    Event ID:	529
    Date:		8/23/2012
    Time:		2:55:28 AM
    User:		NT AUTHORITY\SYSTEM
    Computer:	SXC03
    Description:
    Logon Failure:
     	Reason:		Unknown user name or bad password
     	User Name:	root
     	Domain:		PCHPCT7
     	Logon Type:	3
     	Logon Process:	NtLmSsp 
     	Authentication Package:	MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
     	Workstation Name:	PCHPCT7
    
    
    For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

    My Computer is SXC03 running on Win XP SP3.

    Does this indicates that:

    1. My computer is attempting to login to Workstation PCHPCT7 and fail; OR

    2. Workstation PCHPCT7 is attempting to login to My computer and fail ?

    I have over thousands similar log for Failure Audit in Logon/Logoff.

    I have checked my PC is updated with latest Antivirus DAT/engine and also runs Spyware program to check for infection but nothing found.

    Please advice.

    Thank you.


    ---Packie





    • Edited by Patrick M Wednesday, August 22, 2012 9:44 PM
    Wednesday, August 22, 2012 7:51 PM