Re: Update Post Regarding Logon events after Trend 3.5 Upgrade



Thanks for asking Susan. I don't mind if you do. I checked this morning to
see if I've had new 529 Events in my Security log. There was one close to
the time I was applying Trends suggestion but I think it was shortly before
I completed. There have been none since that time from the .notaccount
user.

Thanks
Jeff

"Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP]" <sbradcpa@xxxxxxxxxxx>
wrote in message news:eO4yBkraHHA.5108@xxxxxxxxxxxxxxxxxxxxxxx
Mind if I blog this?

Jeff Teel wrote:
I contacted Trend about the Logon events that started after upgrading
from Trend 3.0 to 3.5 and here is their suggestion.

-------------------------------------------------------
Trend Response:
Question/concerns/Inquiry: getting Event ID:529

Solutions/Suggestions:

1. Open the C:\Program Files\Trend Micro\Security
Server\PCCSRV\Admin\Utility\TMVS folder.

2. Double-click TMVS.exe and click Settings.

3. Under the Product Query section, clear all the marked check boxes
except for the OfficeScan Corporate Edition/Security Server check box.

4. Click OK.

Please feel free to ask for further clarifications on this matter. We
would gladly continue to assist you.

However, if the issue is successfully resolved and if you have no other
concerns that you would like us to help you with, please reply to this
e-mail at the soonest so that we can close the case.

We are looking forward to your reply and hope that we may continue to
rely on your appreciated patronage.

------------------------------------------------------

I'm not sure why but the file TMVS.exe was not located in the same place
on my server as where Trend said to look. I did not have a folder named
Security Server on my server but the file TMVS.exe was available so I was
still able to perform the suggestion. It appears to have solved the
event errors in the Windows Event Log.

Thanks
Jeff

-----------------------------------------------------
Original Post

After doing an upgrade from CSM 3.0 to CSM 3.5 I've been seeing Logon
failures. What is Trend attempting to access using the .notaccount
username
that would cause these?

Thanks
Jeff

Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 3/8/2007
Time: 9:22:49 PM
User: NT AUTHORITY\SYSTEM
Computer: SBS
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: .notaccount.
Domain: network
Logon Type: 2
Logon Process: Advapi
Authentication Package: Negotiate
Workstation Name: SBS
Caller User Name: SBS$
Caller Domain: network
Caller Logon ID: (0x0,0x3E7)
Caller Process ID: 3024
Transited Services: -
Source Network Address: -
Source Port: -


.



Relevant Pages

  • RE: Event ID 529
    ... ISA is part of the Premium install. ... is that you already have a good security solution in place. ... Logon Failure: ... Caller User Name: MYSVRNAME$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Login Errors Seem to indicate we are being hacked?
    ... I've got ISA configured so it only allows SMTP and RWW, and I use RWWGuard for RWW security, so I'm confident that in my case it can't be anything but SMTP. ... Logon Failure: ... Caller User Name: SERVER01$ ... Ie what is a logon type 3 and what do the caller Login ...
    (microsoft.public.windows.server.sbs)
  • Re: slow iis 6.0 performance
    ... If yes, the security has ... compatible web farm Session replacement for Asp and Asp.Net ... > Logon Failure: ... > Caller User Name: - ...
    (microsoft.public.inetserver.iis)
  • Re: Stop illegal login attempts?
    ... How can I stop illegal login attempts to my SBS box Exchange server? ... I had a guy last night try for over 3 hours to guess my username/password which generated over 610 security errors in the security event log. ... Logon Failure: ... Caller User Name: WX98$ ...
    (microsoft.public.windows.server.sbs)
  • Re: Logon events after upgrading to Trend CSM 3.5
    ... What is Trend attempting to access using the .notaccount ... Logon Failure: ... Caller User Name: SBS$ ... Caller Domain: network ...
    (microsoft.public.windows.server.sbs)