Event Viewer Log on Codes query

solquiff

Reputable
Aug 4, 2015
18
0
4,510
Hi
I am using Windows 7 Home premium and today I was checking the Event viewer and looking at the log on information. The reason is that I turned on my computer and when I came back it was unlocked (i didn't remember unlocking it myself- just powering it up), any way I was looking at the log in information to see if my computer had been accessed remotely or something.

Anyway, there were quite a lot of log on 4624 and a few 4648 codes. Looking at the 4624 ones, there seems to be a variation in the log on type. I have seen type 2, 3 and 5. I have looked back randomly over the past few months and I am seeing the same thing, a mixture of 2,3 and 5. As far as I know, log in type 2 is when you log on physically at the computer by typing in the password on the computer. The others I don't understand, could these be people logging in remotely?

Also, I have been looking further back and I can see that around 10 months ago beside one of the logins (login 4624 type 3) beside workstation it says my girlfriends name. She sometimes uses my computer but there is only one profile on this computer (my one), why would it show up as her workstation when she doesn't have one on this computer. She also isn't very very good with computers so would have no idea how to do something like this.

I am a bit concerned as I also checked in Control Panel- Remote Settings and Allow Remote Assistance was ticked. I have never accessed that part of the system before so it couldn't have been me.Does this sound like a potential hack?

Please help to put my mind at ease.
 
I have been doing some research and it seems log on 2, 3 5 and 7 are quite common etc but I am still confused as to why at certain times my girlfriend's name appears in Workstation Name. My computer only has one user (me). Although she has her own computer, she sometimes uses mine and my password so it is still my user logging on. Is there any reason why the workstation is coming up under her name on my computer. We do not have a home group or anything like that but do share the same wifi connection, maybe it has something to do with that? Here is an example below: I have deleted my girlfriend's name and IP address.

An account was successfully logged on.

Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 3

New Logon:
Security ID: ANONYMOUS LOGON
Account Name: ANONYMOUS LOGON
Account Domain: NT AUTHORITY
Logon ID: 0xe56308
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x0
Process Name: -

Network Information:
Workstation Name: ******
Source Network Address: 192.168.1.35
Source Port: 49744

Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): NTLM V1
Key Length: 128
 

TRENDING THREADS