Jump to content



Photo

Win8 Event ID 4797

windows 8 event id 4797

  • Please log in to reply
6 replies to this topic

#1 AR556

AR556

    Neowinian Senior

  • Joined: 07-August 03

Posted 27 January 2013 - 15:30

Anyone ever see these on their Windows 8 machine in the security section of the log viewer? :wacko:

Event ID 4797

"An attempt was made to query the existence of a blank password for an account."

Subject:
Security ID:
Account Name:
Account Domain:
Logon ID:

Additional Information:
Caller Workstation:
Target Account Name: Guest




#2 DrHaze

DrHaze

    Neowinian

  • Joined: 29-January 13

Posted 29 January 2013 - 02:55

I am getting the same thing
Windows 8 X64 Pro Upgrade from Windows 7 x64
No One seems to be able to answer the question
Avast Antivirus
Comodo 6 Firewall
I get the 4797 for ALL of my accounts, GUEST, Administrator and the other two i have that have admin privileges.
it is at random but regularly/daily goes on

#3 Praetor

Praetor

    ASCii / ANSi Designer

  • Tech Issues Solved: 5
  • Joined: 05-June 02
  • Location: Lisbon
  • OS: Windows Eight dot One dot One 1!one

Posted 29 January 2013 - 02:58

"Target Account Name: Guest"

an attack?

#4 fusi0n

fusi0n

    Don't call it a come back

  • Tech Issues Solved: 3
  • Joined: 08-July 04
  • OS: OSX 10.9\Windows 10\Ubuntu
  • Phone: LG G3

Posted 29 January 2013 - 03:01

"Target Account Name: Guest"

an attack?

That is what I was thinking

#5 DrHaze

DrHaze

    Neowinian

  • Joined: 29-January 13

Posted 29 January 2013 - 04:37

It's definately some sort of attack. 21 times all accounts.

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 1/28/2013 11:34:08 PM
Event ID: 4797
Task Category: User Account Management
Level: Information
Keywords: Audit Success
User: N/A
Computer: phenom
Description:
An attempt was made to query the existence of a blank password for an account.

Subject:
Security ID: phenom\crusader
Account Name: crusader
Account Domain: phenom
Logon ID: 0xA068D

Additional Information:
Caller Workstation: PHENOM
Target Account Name: DrHaze
Target Account Domain: phenom
Event Xml:
<Event xmlns="http://schemas.micro.../events/event">
<System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>4797</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>13824</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2013-01-29T04:34:08.308305800Z" />
<EventRecordID>42164</EventRecordID>
<Correlation />
<Execution ProcessID="1000" ThreadID="3832" />
<Channel>Security</Channel>
<Computer>phenom</Computer>
<Security />
</System>
<EventData>
<Data Name="SubjectUserSid">S-1-5-21-1124263850-194828415-1399416522-1001</Data>
<Data Name="SubjectUserName">crusader</Data>
<Data Name="SubjectDomainName">phenom</Data>
<Data Name="SubjectLogonId">0xa068d</Data>
<Data Name="Workstation">PHENOM</Data>
<Data Name="TargetUserName">DrHaze</Data>
<Data Name="TargetDomainName">phenom</Data>
</EventData>
</Event>

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 1/28/2013 11:34:08 PM
Event ID: 4797
Task Category: User Account Management
Level: Information
Keywords: Audit Success
User: N/A
Computer: phenom
Description:
An attempt was made to query the existence of a blank password for an account.

Entire log located here... http://pastie.org/5953014

#6 Grinch

Grinch

    Developer

  • Tech Issues Solved: 5
  • Joined: 26-September 09
  • Location: Wisconsin
  • OS: Windows 8.1.1 | WP8.1.1
  • Phone: Nokia Lumia 925

Posted 29 January 2013 - 04:43

^ Hey bud, try using pastie.org or something instead of making a giant post. :)

#7 DrHaze

DrHaze

    Neowinian

  • Joined: 29-January 13

Posted 29 January 2013 - 14:02

sorry didn't mean to post the whole thing. I can't seem to edit it now either