2 Replies Latest reply on Mar 8, 2013 11:40 AM by mark4551

    Event ID 4797

      Log Name:      Security

      Source:        Microsoft-Windows-Security-Auditing

      Date:          3/7/2013 6:35:11 PM

      Event ID:      4797

      Task Category: User Account Management

      Level:         Information

      Keywords:      Audit Success

      User:          N/A

      Computer:      sara

      Description:

      An attempt was made to query the existence of a blank password for an account.

       

       

      Subject:

                Security ID:                    sara\Mark

                Account Name:                    Mark

                Account Domain:                    sara

                Logon ID:                    0x2FBFF

       

       

      Additional Information:

                Caller Workstation:          SARA

                Target Account Name:          Guest

                Target Account Domain:          sara

       

       

      Literally get at least a hundred of these a day...also along with event's 4672,4624,4634,4648(logon was attempted with explicit credintials)

      Looked around online and seems like this is a common theme with win8...doesn't matter which version and no one has any idea what it's for. These entries post usually after im already logged into my account. Mcafee antivirius plus is up-to-date, along with windows...did full scans and came back with nothing. If you look at additional info you see it's targeting my guest account which is disabled, also have logs for admin account and the account I use, along with some other weird domains like homegroup$

       

      any help or thoughts would be appreciated just trying to make sure this is just a bug microsoft needs to figure out!