A logon was attempted using explicit credentials. event ID 4648

0

i am seeing this error on 3 pcs on the network and on our server, they are coming from 1 account that has been deleted and 2 that are still on the PC's. we are on a regular workgroup network with 2012 server std. we have Changed everybody's passwords recently. No services are using any accounts with passwords we changed. i am seeing this event log every 15 minutes. There are many task's but i dont see any with the user that has been deleted or other 2 users. This has been driving me crazy and i have to disable our account lockout policy since it is locking out 2 accounts on the server side....Any help would be great!?

A logon was attempted using explicit credentials.

Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x14CEB Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used: Account Name: Melissa Account Domain: MELISSA-PC Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server: Target Server Name: SRV2008 Additional Information: SRV2008

Process Information: Process ID: 0x4 Process Name:

Network Information: Network Address: fe80::888:b5b0:27fb:13a0 Port: 445

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.

Renho17

Posted 2017-08-02T23:43:48.453

Reputation: 1

I also checked the credential manager and no luck.. – Renho17 – 2017-08-02T23:44:37.317

Remove MELISSA-PC from the workgroup – Ramhound – 2017-08-02T23:45:25.353

No answers