Hello,
I have a system that many Event ID 4624 Successful (Anonmymous) Logon with the corresponding 4634 Logoff's. The account name is ANONYMOUS, with NO network information what so ever on any of the event entries with the account domain as NT AUTHORITY. There is a total of 1185 over a 12 month period.
These are all Logon Type 3 (network)
Are there any legitimate reasons for this? How come there is NO source IP or workstation name listed on any of these? This is on a Windows Vista system. There is an a IIS_IUSR account, but the system is not suppose to be running a webservice. Though not sure how I can check. Is there any registry keys that would show this? All I have is a dead system image, and I can't boot it up.
Thanks,
I have a system that many Event ID 4624 Successful (Anonmymous) Logon with the corresponding 4634 Logoff's. The account name is ANONYMOUS, with NO network information what so ever on any of the event entries with the account domain as NT AUTHORITY. There is a total of 1185 over a 12 month period.
These are all Logon Type 3 (network)
Are there any legitimate reasons for this? How come there is NO source IP or workstation name listed on any of these? This is on a Windows Vista system. There is an a IIS_IUSR account, but the system is not suppose to be running a webservice. Though not sure how I can check. Is there any registry keys that would show this? All I have is a dead system image, and I can't boot it up.
Thanks,