Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations wOOdy-Soft on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

getting knocked off the 2003 active directory

Status
Not open for further replies.

jwa6

Programmer
Sep 16, 2002
152
US
we are on a active directory(2003). I am on a XP pro pc here.
I am getting locked out of the network while using this pc.


I see some of this in the event viewer:


Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861
Description:
The Windows Firewall has detected an application listening for incoming
traffic.

I have the IE firewall shutoff.

Name: -
Path: C:\WINDOWS\UTLite.exe
Process identifier: 2172
Event Type: Failure Audit
Event Source: Security
Event Category: Detailed Tracking
Event ID: 861


The Windows Firewall has detected an application listening for incoming
traffic.


Name: -
Path: C:\WINDOWS\system32\lsass.exe
Process identifier: 600
User account: SYSTEM
User domain: NT AUTHORITY

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Description:
The Security System detected an attempted downgrade attack for server
exchangeAB\etcetc. The failure code from authentication protocol
Kerberos was "The user account has been automatically locked because
too many invalid logon attempts or password change attempts have been
requested.
Description:

The Security System could not establish a secured connection with the
server exchangeAB\etcetc. No authentication protocol was available


I use a utility called CCleaner 2x a day or so. I have this set to
clean windows temp files as well. Is this an issue?


Or do I have an intrider?


thanks


 
Have a look here.

Error Message:
The user account has been automatically locked because too many invalid logon attempts or password change attempts have been requested.

User Action:
This Windows 2000 Executive STATUS message is a warning. Choose one of the options from the message box and then contact your system administrator.



Event ID: 40960

Any other Event ID errors try the main site.
 
I found the problem.

I am using a utlity called CCcleaner. I am deleted what cccleaner calls "windows temp files" . I shut that switch off. I no longer get kicked off of the network.

jima
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top