Recommended Posts

Anyone ever see these on their Windows 8 machine in the security section of the log viewer? :wacko:

Event ID 4797

"An attempt was made to query the existence of a blank password for an account."

Subject:

Security ID:

Account Name:

Account Domain:

Logon ID:

Additional Information:

Caller Workstation:

Target Account Name: Guest

Link to comment
https://www.neowin.net/forum/topic/1133164-win8-event-id-4797/
Share on other sites

I am getting the same thing

Windows 8 X64 Pro Upgrade from Windows 7 x64

No One seems to be able to answer the question

Avast Antivirus

Comodo 6 Firewall

I get the 4797 for ALL of my accounts, GUEST, Administrator and the other two i have that have admin privileges.

it is at random but regularly/daily goes on

It's definately some sort of attack. 21 times all accounts.

Log Name: Security

Source: Microsoft-Windows-Security-Auditing

Date: 1/28/2013 11:34:08 PM

Event ID: 4797

Task Category: User Account Management

Level: Information

Keywords: Audit Success

User: N/A

Computer: phenom

Description:

An attempt was made to query the existence of a blank password for an account.

Subject:

Security ID: phenom\crusader

Account Name: crusader

Account Domain: phenom

Logon ID: 0xA068D

Additional Information:

Caller Workstation: PHENOM

Target Account Name: DrHaze

Target Account Domain: phenom

Event Xml:

<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">

<System>

<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />

<EventID>4797</EventID>

<Version>0</Version>

<Level>0</Level>

<Task>13824</Task>

<Opcode>0</Opcode>

<Keywords>0x8020000000000000</Keywords>

<TimeCreated SystemTime="2013-01-29T04:34:08.308305800Z" />

<EventRecordID>42164</EventRecordID>

<Correlation />

<Execution ProcessID="1000" ThreadID="3832" />

<Channel>Security</Channel>

<Computer>phenom</Computer>

<Security />

</System>

<EventData>

<Data Name="SubjectUserSid">S-1-5-21-1124263850-194828415-1399416522-1001</Data>

<Data Name="SubjectUserName">crusader</Data>

<Data Name="SubjectDomainName">phenom</Data>

<Data Name="SubjectLogonId">0xa068d</Data>

<Data Name="Workstation">PHENOM</Data>

<Data Name="TargetUserName">DrHaze</Data>

<Data Name="TargetDomainName">phenom</Data>

</EventData>

</Event>

Log Name: Security

Source: Microsoft-Windows-Security-Auditing

Date: 1/28/2013 11:34:08 PM

Event ID: 4797

Task Category: User Account Management

Level: Information

Keywords: Audit Success

User: N/A

Computer: phenom

Description:

An attempt was made to query the existence of a blank password for an account.

Entire log located here... http://pastie.org/5953014

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Couple years ago I got a brand new 4TB Samsung 990 Pro for $250 during Black Friday
    • Thanks
    • Can confirm, I've built stuff for others and no complaints using their products.
    • Yes I agree, it's annoying. You can now miss tabs unless you point low enough.
    • Sysinternals Suite 2026.17.06 by Razvan Serea The Sysinternals Suite is a comprehensive package of advanced Windows utilities created by Mark Russinovich, who launched the Sysinternals website in 1996 to share his system tools and technical resources. This suite combines a wide range of troubleshooting and diagnostic tools, including Process Explorer, Process Monitor, Sysmon, Autoruns, ProcDump, the PsTools collection, and many others. It provides everything IT professionals and developers need to manage, monitor, and troubleshoot Windows systems and applications. The Suite bundles all of the core troubleshooting utilities along with their help files. Non-troubleshooting extras—such as the BSOD Screen Saver or NotMyFault—are excluded. In addition to the well-known tools, it also includes AccessChk, Autologon, Ctrl2Cap, DiskView, Disk Usage (DU), LogonSessions, PageDefrag, PsLogList, PsPasswd, RegMon, RootkitRevealer, TCPView, VMMap, ZoomIt, and more. Sysinternals Suite 2026.17.06 changelog: Autoruns v14.3 - This update to Autoruns, a utility for monitoring startup items, adds bug fixes and improves the command-line application autorunsc. ZoomIt v12.1 - This update to ZoomIt, a screen magnification and annotation tool, adds image backgrounds, webcam background blur and microphone noise cancellation support. Coreinfo v4.01 - This update to Coreinfo, a tool that reports processor, socket, NUMA memory, and cache topology of a system, as well as processor features supported, adds support for new processor features. DebugView v5.02 - This update to DebugView, a tool for displaying both kernel-mode and Win32 debug output, adds Ctrl-Shift-A support for selecting all output, and agent skills support for the CLI utility. LiveKd v5.64 - This update to LiveKd, a utility that allows running the kernel debugger on a live system, fixes a debugging privileges issue. ProcDump 3.5.2 for Linux - This update to ProcDump for Linux, a tool for capturing process dumps, adds .NET counters and a custom core dumper. Process Monitor v4.04 - This update to Process Monitor, a utility for observing real-time file system, Registry, and process or thread activity, adds some bug fixes Sysmon v15.21 - This update to Sysmon, an advanced host security monitoring tool, adds some bug fixes. Download: Sysinternals Suite 2026.17.06 | 168.0 MB (Freeware) Download: Sysinternals Suite for ARM64 | 15.4 MB Link: Sysinternals Suite Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      eurospharma62 earned a badge
      One Month Later
    • Week One Done
      With What earned a badge
      Week One Done
    • Week One Done
      Harris Gilbert earned a badge
      Week One Done
    • One Month Later
      Vincian earned a badge
      One Month Later
    • First Post
      Jocimo earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      542
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      85
    4. 4
      ATLien_0
      64
    5. 5
      neufuse
      64
  • Tell a friend

    Love Neowin? Tell a friend!