Sign in to follow this  
Followers 0

Win8 Event ID 4797


7 posts in this topic

Posted

Anyone ever see these on their Windows 8 machine in the security section of the log viewer? :wacko:

Event ID 4797

"An attempt was made to query the existence of a blank password for an account."

Subject:

Security ID:

Account Name:

Account Domain:

Logon ID:

Additional Information:

Caller Workstation:

Target Account Name: Guest

Share this post


Link to post
Share on other sites

Posted

I am getting the same thing

Windows 8 X64 Pro Upgrade from Windows 7 x64

No One seems to be able to answer the question

Avast Antivirus

Comodo 6 Firewall

I get the 4797 for ALL of my accounts, GUEST, Administrator and the other two i have that have admin privileges.

it is at random but regularly/daily goes on

Share this post


Link to post
Share on other sites

Posted

"Target Account Name: Guest"

an attack?

Share this post


Link to post
Share on other sites

Posted

"Target Account Name: Guest"

an attack?

That is what I was thinking

Share this post


Link to post
Share on other sites

Posted

It's definately some sort of attack. 21 times all accounts.

Log Name: Security

Source: Microsoft-Windows-Security-Auditing

Date: 1/28/2013 11:34:08 PM

Event ID: 4797

Task Category: User Account Management

Level: Information

Keywords: Audit Success

User: N/A

Computer: phenom

Description:

An attempt was made to query the existence of a blank password for an account.

Subject:

Security ID: phenom\crusader

Account Name: crusader

Account Domain: phenom

Logon ID: 0xA068D

Additional Information:

Caller Workstation: PHENOM

Target Account Name: DrHaze

Target Account Domain: phenom

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

<System>

<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

<EventID>4797</EventID>

<Version>0</Version>

<Level>0</Level>

<Task>13824</Task>

<Opcode>0</Opcode>

<Keywords>0x8020000000000000</Keywords>

<TimeCreated SystemTime="2013-01-29T04:34:08.308305800Z" />

<EventRecordID>42164</EventRecordID>

<Correlation />

<Execution ProcessID="1000" ThreadID="3832" />

<Channel>Security</Channel>

<Computer>phenom</Computer>

<Security />

</System>

<EventData>

<Data Name="SubjectUserSid">S-1-5-21-1124263850-194828415-1399416522-1001</Data>

<Data Name="SubjectUserName">crusader</Data>

<Data Name="SubjectDomainName">phenom</Data>

<Data Name="SubjectLogonId">0xa068d</Data>

<Data Name="Workstation">PHENOM</Data>

<Data Name="TargetUserName">DrHaze</Data>

<Data Name="TargetDomainName">phenom</Data>

</EventData>

</Event>

Log Name: Security

Source: Microsoft-Windows-Security-Auditing

Date: 1/28/2013 11:34:08 PM

Event ID: 4797

Task Category: User Account Management

Level: Information

Keywords: Audit Success

User: N/A

Computer: phenom

Description:

An attempt was made to query the existence of a blank password for an account.

Entire log located here... http://pastie.org/5953014

Share this post


Link to post
Share on other sites

Posted

^ Hey bud, try using pastie.org or something instead of making a giant post. :)

Share this post


Link to post
Share on other sites

Posted

sorry didn't mean to post the whole thing. I can't seem to edit it now either

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0

  • Recently Browsing   0 members

    No registered users viewing this page.