Click here to get back home

need some help on this one

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
need some help on this one Mike 06-11-2007
Posted by Mike on June 11, 2007, 2:00 pm
Please log in for more thread options
lets just start off by saying I'm a developer and no longer a server
admin BUT I'm doing some server admin work to help out.

Ok, on one of my Windows 2003 servers I keep getting this error in the event
viewer and I've done some research on it and I'm getting information from
spy ware, a virus to something Microsoft uses to even a worm. Can anyone
shed some light on this for me?

Logon Failure:
Reason: Unknown user name or bad password
User Name: testUSER
Domain: Bulldog
Logon Type: 4
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: FileSystemServerABCD01
Caller User Name: userName
Caller Domain: Bulldog
Caller Logon ID: (0x0,0x2990D)
Caller Process ID: 4076
Transited Services: -
Source Network Address: -
Source Port: -


For more information, see Help and Support Center at

any suggestions on what can be causing this? an update. patch, etc anything?




Posted by Danny Sanders on June 11, 2007, 4:35 pm
Please log in for more thread options
It's a virus/trojan.


Do you have any Antivirus installed?



hth
DDS

> lets just start off by saying I'm a developer and no longer a
> server admin BUT I'm doing some server admin work to help out.
>
> Ok, on one of my Windows 2003 servers I keep getting this error in the
> event viewer and I've done some research on it and I'm getting information
> from spy ware, a virus to something Microsoft uses to even a worm. Can
> anyone shed some light on this for me?
>
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: testUSER
> Domain: Bulldog
> Logon Type: 4
> Logon Process: Advapi
> Authentication Package: Negotiate
> Workstation Name: FileSystemServerABCD01
> Caller User Name: userName
> Caller Domain: Bulldog
> Caller Logon ID: (0x0,0x2990D)
> Caller Process ID: 4076
> Transited Services: -
> Source Network Address: -
> Source Port: -
>
>
> For more information, see Help and Support Center at
>
> any suggestions on what can be causing this? an update. patch, etc
> anything?
>
>
>



Posted by Mike on June 14, 2007, 3:46 pm
Please log in for more thread options
yes, Symnatec is installed on the server.

so anything with this: Advapi its a virus/trojan?
then why when I googled it I got some information that windows uses it for
its login?

how can i find out what exactly its trying to run and why wont' my antivirus
pick it up?




> It's a virus/trojan.
>
>
> Do you have any Antivirus installed?
>
>
>
> hth
> DDS
>
>> lets just start off by saying I'm a developer and no longer a
>> server admin BUT I'm doing some server admin work to help out.
>>
>> Ok, on one of my Windows 2003 servers I keep getting this error in the
>> event viewer and I've done some research on it and I'm getting
>> information from spy ware, a virus to something Microsoft uses to even a
>> worm. Can anyone shed some light on this for me?
>>
>> Logon Failure:
>> Reason: Unknown user name or bad password
>> User Name: testUSER
>> Domain: Bulldog
>> Logon Type: 4
>> Logon Process: Advapi
>> Authentication Package: Negotiate
>> Workstation Name: FileSystemServerABCD01
>> Caller User Name: userName
>> Caller Domain: Bulldog
>> Caller Logon ID: (0x0,0x2990D)
>> Caller Process ID: 4076
>> Transited Services: -
>> Source Network Address: -
>> Source Port: -
>>
>>
>> For more information, see Help and Support Center at
>>
>> any suggestions on what can be causing this? an update. patch, etc
>> anything?
>>
>>
>>
>
>



Posted by Suheyla on June 12, 2007, 10:58 am
Please log in for more thread options
Hi Mike,
Danny is rigth, but if you have already installed one then :

The log says that it is logon type 4 that means batch logon, so there is a
program tries to connect some resources, and also it gave the caller process
ID ; if you check the windows task manager with process id (view -- select
column) then you can find which program is generating this error.

Suheyla

"Mike" wrote:

> lets just start off by saying I'm a developer and no longer a server
> admin BUT I'm doing some server admin work to help out.
>
> Ok, on one of my Windows 2003 servers I keep getting this error in the event
> viewer and I've done some research on it and I'm getting information from
> spy ware, a virus to something Microsoft uses to even a worm. Can anyone
> shed some light on this for me?
>
> Logon Failure:
> Reason: Unknown user name or bad password
> User Name: testUSER
> Domain: Bulldog
> Logon Type: 4
> Logon Process: Advapi
> Authentication Package: Negotiate
> Workstation Name: FileSystemServerABCD01
> Caller User Name: userName
> Caller Domain: Bulldog
> Caller Logon ID: (0x0,0x2990D)
> Caller Process ID: 4076
> Transited Services: -
> Source Network Address: -
> Source Port: -
>
>
> For more information, see Help and Support Center at
>
> any suggestions on what can be causing this? an update. patch, etc anything?
>
>
>
>

Posted by Mike on June 14, 2007, 3:54 pm
Please log in for more thread options
I found out what is running and failing. Its the OWSTimer.exe file. I
googled it and some say its spyware and some say its part of SharePoint. Now
I do have SharePoint on my server. So am I stuck with this error all the
time now or is there a way to fix it?



> Hi Mike,
> Danny is rigth, but if you have already installed one then :
>
> The log says that it is logon type 4 that means batch logon, so there is a
> program tries to connect some resources, and also it gave the caller
> process
> ID ; if you check the windows task manager with process id (view -- select
> column) then you can find which program is generating this error.
>
> Suheyla
>
> "Mike" wrote:
>
>> lets just start off by saying I'm a developer and no longer a
>> server
>> admin BUT I'm doing some server admin work to help out.
>>
>> Ok, on one of my Windows 2003 servers I keep getting this error in the
>> event
>> viewer and I've done some research on it and I'm getting information from
>> spy ware, a virus to something Microsoft uses to even a worm. Can anyone
>> shed some light on this for me?
>>
>> Logon Failure:
>> Reason: Unknown user name or bad password
>> User Name: testUSER
>> Domain: Bulldog
>> Logon Type: 4
>> Logon Process: Advapi
>> Authentication Package: Negotiate
>> Workstation Name: FileSystemServerABCD01
>> Caller User Name: userName
>> Caller Domain: Bulldog
>> Caller Logon ID: (0x0,0x2990D)
>> Caller Process ID: 4076
>> Transited Services: -
>> Source Network Address: -
>> Source Port: -
>>
>>
>> For more information, see Help and Support Center at
>>
>> any suggestions on what can be causing this? an update. patch, etc
>> anything?
>>
>>
>>
>>




Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap