Event Log High Number of Failed Login Attempts - Windows 2008 R2 File Server
we have unique setup our users login local systems account , username matches domain username , account pass through authentication.
every see failed login attempt on server's event log, yesterday server logged on 200 failed login attempts hour , half. while reported not access file server, others seemed fine. nothing on server pointed alarming, , users able connect without without intervention.
one possibility thinking of persistent network connection being made invalid password.
we scanned 1 of systems virus and/or hacked possibilities , found nothing.
on same machine, renamed user account , noticed login failure next day new login name. although number of failed attempts small compared 20+ event logs previous day, interesting see new named had failed @ least once well.
something peculiar 1 of our machines attempted login server system belonged else account not resident on machine itself. the thing think of @ 1 time did quick mapping via cmd prompt file transfer, wasn't permanent drive mapping.
here few things have tried far:
- ran virus scan sophos 10.0, housecall, tdskiller kaspersky, microsoft security essentials , avg rescue cd none of them found anything
- ran net use * /delete in every profile on system in question make sure system not have persistent drive mapping
- delete in hkey_current_user\software
- delete shortcuts created user point shared drive
- use process explorer , hijackthis , didn't find out of ordinary
- no problem found when login new user brand new profile on same system. seems profile specific issue.
any thoughts and/or suggestions appreciated.
Windows Server > File Services and Storage
Comments
Post a Comment