Solved Event 4625?


RaveBlack

Active member
Local time
6:46 AM
Posts
10
OS
Windows 11 24H2
Hello, currently running 23H2 (OS Build 22631.5624). I don't usually make it a habit of browsing my event logs, but while checking if my slightly dodgy wifi was working correctly in the logs yesterday (unrelated issue, it roams like crazy if on a certain band), I entered the security logs and discovered something a little strange going on.

From what I can tell, this has been happening once almost every night for most of the month, prob'ly longer. Three event 4625s. Here's the first one. The guest account is very much disabled.
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 7/30/2025 12:13:21 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: (My computer)
Description:
An account failed to log on.

Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 3

Account For Which Logon Failed:
Security ID: NULL SID
Account Name: guest
Account Domain: -

Failure Information:
Failure Reason: Account currently disabled.
Status: 0xC000006E
Sub Status: 0xC0000072

Process Information:
Caller Process ID: 0x0
Caller Process Name: -

Network Information:
Workstation Name: -
Source Network Address: (My computer's internal IP!)
Source Port: 62875

Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

Exactly three seconds later, I get two more. The second one is almost identical to that one save for a source port change (the second and third are from the same port, the first isn't), and the third one is slightly different.

Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 7/30/2025 12:13:24 AM
Event ID: 4625
Task Category: Logon
Level: Information
Keywords: Audit Failure
User: N/A
Computer: (My computer)
Description:
An account failed to log on.

Subject:
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 3

Account For Which Logon Failed:
Security ID: NULL SID
Account Name:
Account Domain: -

Failure Information:
Failure Reason: Unknown user name or bad password.
Status: 0xC000006D
Sub Status: 0xC0000064

Process Information:
Caller Process ID: 0x0
Caller Process Name: -

Network Information:
Workstation Name: -
Source Network Address: (My computer's internal IP!)
Source Port: 62882

Detailed Authentication Information:
Logon Process: NtLmSsp
Authentication Package: NTLM
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

While it's not exactly at the same time, it's fairly uniform as to when it pops up. Today's was exactly three seconds off from yesterday's time, for example. I'm not getting random amounts, just these three and the only thing that changes is the source port. I've scanned with Malwarebytes, Norton 360, ESET (the online on demand version which I'm told doesn't conflict), and adwcleaner, all four have come back clean so I don't think it's malware-related. My computer also looks to be working normally. I've tried googling and found that someone had something that sounds almost exactly like this, but they never received a proper answer. I mainly want to know what's potentially causing it and if it's safe to leave alone. Thank you in advance!
 

My Computer My Computer

At a glance

Windows 11 24H2Intel i3-12100F8 GB NeoForza Mars, currentlyNVIDIA GeForce GTX 1650
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
ibuypower
CPU
Intel i3-12100F
Motherboard
AsRock B660M-C
Memory
8 GB NeoForza Mars, currently
Graphics Card(s)
NVIDIA GeForce GTX 1650
Logon type 3 means it's a network authentication event, but since the source is your local IP it's something on your computer. This looks very much like a vulnerability asset scanner. The frequency suggests a scheduled activity and the activity itself looks like it's checking to see if anonymous/guest access is allowed
 

My Computer My Computer

At a glance

Linux Mint
OS
Linux Mint
Computer type
Laptop
Manufacturer/Model
System76 Lemur Pro
Logon type 3 means it's a network authentication event, but since the source is your local IP it's something on your computer. This looks very much like a vulnerability asset scanner. The frequency suggests a scheduled activity and the activity itself looks like it's checking to see if anonymous/guest access is allowed
You pointed me in exactly the right direction. For a bit, I thought, "How could I have something like that on my computer?" then I realized that I just might have and who the culprit likely was.

To test it, I ran a scan with Norton 360 twice, and both times I was able to reproduce the events exactly as I detailed above. I have no idea why it's been running independently (Norton's been a pain since the obviously beta version 24 was dropped on everyone), but at least now I know what it is and that it's not anything horrifying. Thank you.
 

My Computer My Computer

At a glance

Windows 11 24H2Intel i3-12100F8 GB NeoForza Mars, currentlyNVIDIA GeForce GTX 1650
OS
Windows 11 24H2
Computer type
PC/Desktop
Manufacturer/Model
ibuypower
CPU
Intel i3-12100F
Motherboard
AsRock B660M-C
Memory
8 GB NeoForza Mars, currently
Graphics Card(s)
NVIDIA GeForce GTX 1650
Back
Top Bottom