Event Log High Number of Failed Login Attempts - Windows 2008 R2 File Server


we have unique setup our users login local systems account , username matches domain username , account pass through authentication.

every see failed login attempt on server's event log, yesterday server logged on 200 failed login attempts hour , half. while reported not access file server, others seemed fine.  nothing on server pointed alarming, , users able connect without without intervention.

one possibility thinking of persistent network connection being made invalid password.

we scanned 1 of systems virus and/or hacked possibilities , found nothing.

on same machine, renamed user account , noticed login failure next day new login name.  although number of failed attempts small compared 20+ event logs previous day, interesting see new named had failed @ least once well.

something peculiar 1 of our machines attempted login server system belonged else account not resident on machine itself.  the thing think of @ 1 time did quick mapping via cmd prompt file transfer, wasn't permanent drive mapping.

here few things have tried far:

- ran virus scan sophos 10.0, housecall, tdskiller kaspersky, microsoft security essentials , avg rescue cd none of them found anything 

- ran net use * /delete in every profile on system in question make sure system not have persistent drive mapping

- delete in hkey_current_user\software\microsoft\windows\currentversion\explorer\map network drive mru

- delete shortcuts created user point shared drive

- use process explorer , hijackthis , didn't find out of ordinary

- no problem found when login new user brand new profile on same system. seems profile specific issue. 

any thoughts and/or suggestions appreciated.  

 




Windows Server  >  File Services and Storage



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file