Event Log - Failure Audit 560 - NetBT_Tcpip
I have an XP machine on my network (Server 2003 PDC / Server 2000 backup DC) that is experiencing two of these errors every second - filling up my Security log and then booting my users off the network.
Just a bit of background on the network: This is an established network (two DC's, both Server 2000 with 7 XP seats). I recently demoted one of the 2000 DCs and installed Server 2003. the Server 2003 machine is my PDC.
in searching Technet I found this link:
http://support.microsoft.com/kb/914962 but the latest server pack and updates have been installed on each machine.
Can someone point me in the right direction to change the permissions so I can stop these failures? only regular users get these - not admins....
Many Thanks!
July 13th, 2011 12:44pm
Here is the log event:
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
Event ID: 560
Date: 7/13/2011
Time: 11:20:26 AM
User: MYDOMAIN\RegUser
Computer: MYCOMPUTER
Description:
Object Open:
Object Server: Security
Object Type: File
Object Name: \Device \NetBT_Tcpip_{ 6DC7F I DF-CF5A-4242-A8CDFOD738773904}
Handle ID: -
Operation ID: {0,1161508}
Process ID: 872
Image File Name: C:\WINNT\explorer.exe
Primary User Name: RegUser
Primary Domain: MYDOMAIN
Primary Logon ID: (0x0,0xFA399)
Client User Name:
Client Domain:
Client Logon ID:
Accesses: SYNCHRONIZE
ReadData (or ListDirectory)
WriteData (or AddFile)
Privileges:
Restricted Sid Count: 0
Event Type: Failure Audit
Event Source: Security
Event Category: Object Access
The process ID is always 872
Free Windows Admin Tool Kit Click here and download it now
July 13th, 2011 12:58pm