- Local time
- 9:53 PM
- Messages
- 60
Greetings Gents,
I have an issue I'm trying to resolve with a logon (Type 3) from another PC (In my Workgroup) through my network to my main PC and can't seem to prevent this logon from occurring through the Local Security Policy settings so I don't know if it's a normal Windows process from the networked PC or an outside force attempting to attack my highly secured PC through the network homegroup.
Network:
All 3 PC's running Windows 7 Pro64 bit and Ultimate32 bit connected to a router.... Cisco DPC3848VM which also controls 3 TIVO boxs and the main PC is sharing NOTHING with the other PC's. Two PC's are direct connect through ethernet cable and the problem PC through wireless TPCLink network card Below is the eventlog I'm addressing.
I have several of these in event viewer and notice the log on ID's tend to change...
Logon ID: 0x3c7d85b
Logon ID: 0x3b39a89
Logon ID: 0x3b39a65
Logon ID: 0x39b183f
I've disabled the Guest Account and show only one account as being active and made sure no drive was sharing anything. Ran many tools on the problem PC which includes FRST (deep scan tool) looking for malware/hacks and can find nothing. I can't find anything in Wireshark logs that shows data is being moved but with the dam TIVO boxs talking all the time it's hard to weed though the logs even when you try and filter it.
Going backward through event logs this started around 6-25-2017 and I had no previous entries and no changes to the network or homegroup.
Anyone have an idea on whats going on? Can supply more info if needed. Please move the post to the correct subforum if I've posted in the wrong place.
I have an issue I'm trying to resolve with a logon (Type 3) from another PC (In my Workgroup) through my network to my main PC and can't seem to prevent this logon from occurring through the Local Security Policy settings so I don't know if it's a normal Windows process from the networked PC or an outside force attempting to attack my highly secured PC through the network homegroup.
Network:
All 3 PC's running Windows 7 Pro64 bit and Ultimate32 bit connected to a router.... Cisco DPC3848VM which also controls 3 TIVO boxs and the main PC is sharing NOTHING with the other PC's. Two PC's are direct connect through ethernet cable and the problem PC through wireless TPCLink network card Below is the eventlog I'm addressing.
Code:
An account was successfully logged on.
Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0
Logon Type: 3
New Logon:
Security ID: ANONYMOUS LOGON
Account Name: ANONYMOUS LOGON
Account Domain: NT AUTHORITY
Logon ID: 0x4e2d2
Logon GUID: {00000000-0000-0000-0000-000000000000}
Process Information:
Process ID: 0x0
Process Name: -
Network Information:
Workstation Name:
Source Network Address: -
Source Port: -
Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): NTLM V1
Key Length: 0
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4624</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12544</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2017-08-12T17:38:51.393200100Z" />
<EventRecordID>52245</EventRecordID>
<Correlation />
<Execution ProcessID="808" ThreadID="884" />
<Channel>Security</Channel>
<Computer>Microbell-PC</Computer>
<Security />
</System>
- <EventData>
<Data Name="SubjectUserSid">S-1-0-0</Data>
<Data Name="SubjectUserName">-</Data>
<Data Name="SubjectDomainName">-</Data>
<Data Name="SubjectLogonId">0x0</Data>
<Data Name="TargetUserSid">S-1-5-7</Data>
<Data Name="TargetUserName">ANONYMOUS LOGON</Data>
<Data Name="TargetDomainName">NT AUTHORITY</Data>
<Data Name="TargetLogonId">0x4e2d2</Data>
<Data Name="LogonType">3</Data>
<Data Name="LogonProcessName">NtLmSsp</Data>
<Data Name="AuthenticationPackageName">NTLM</Data>
<Data Name="WorkstationName" />
<Data Name="LogonGuid">{00000000-0000-0000-0000-000000000000}</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">NTLM V1</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0x0</Data>
<Data Name="ProcessName">-</Data>
<Data Name="IpAddress">-</Data>
<Data Name="IpPort">-</Data>
</EventData>
</Event>
I have several of these in event viewer and notice the log on ID's tend to change...
Logon ID: 0x3c7d85b
Logon ID: 0x3b39a89
Logon ID: 0x3b39a65
Logon ID: 0x39b183f
I've disabled the Guest Account and show only one account as being active and made sure no drive was sharing anything. Ran many tools on the problem PC which includes FRST (deep scan tool) looking for malware/hacks and can find nothing. I can't find anything in Wireshark logs that shows data is being moved but with the dam TIVO boxs talking all the time it's hard to weed though the logs even when you try and filter it.
Going backward through event logs this started around 6-25-2017 and I had no previous entries and no changes to the network or homegroup.
Anyone have an idea on whats going on? Can supply more info if needed. Please move the post to the correct subforum if I've posted in the wrong place.
My Computer
- Computer type
- PC/Desktop
- Computer Manufacturer/Model Number
- Custom Build
- OS
- Windows 7 Pro 64bit SP1+Updates
- CPU
- Intel I3 6100
- Motherboard
- MSI Z170a Gaming 3 Bios ver a.4
- Memory
- G.Skill Ripjaws V Series 16GB (2 x 8GB) DDR4 2133mhz
- Graphics Card(s)
- MSI GTX 960 GAMING 100ME 2GB
- Sound Card
- X-Fi xtremegamer fatal1ty pro series
- Monitor(s) Displays
- LG 32MP58HQ-P 32"
- Screen Resolution
- 1920X1080
- Hard Drives
- Samsung 850EVO SSD 250GB
4 WD HD
- PSU
- EVGA SuperNova 650 G2 650w
- Case
- Thermaltake Armor II Tower
- Cooling
- 6 Fan air cooled modded case
- Keyboard
- Logitech G15
- Mouse
- Logitech G5
- Internet Speed
- Cable 120MB/3MB
- Antivirus
- Avast Ver 12.1.2272
- Browser
- Chrome