Having installed Bitdefender Total Security on Windows 11 recently, I am noticing strange Event Viewer entries. Every few minutes, I am getting an Audit Failure 4625 event, "An account failed to log on."
It is always preceded by an also worrying 4723 Audit Success event "An attempt was made to change an account's password." I've had 24 of these event pairs in the last hour.
Doing some googling, there has been talk of Bitdefender being responsible for these. Please can anyone confirm this? It is superficially worrying and would be good to know if BD is behind it so I can relax!
<EventID>4625</EventID>
<EventData>
<Data Name="SubjectUserSid">S-1-5-18</Data>
<Data Name="SubjectUserName">REDACTED$</Data>
<Data Name="SubjectDomainName">WORKGROUP</Data>
<Data Name="SubjectLogonId">0x3e7</Data>
<Data Name="TargetUserSid">S-1-0-0</Data>
<Data Name="TargetUserName">Administrator</Data>
<Data Name="TargetDomainName">REDACTED</Data>
<Data Name="Status">0xc000006e</Data>
<Data Name="FailureReason">%%2310</Data>
<Data Name="SubStatus">0xc0000072</Data>
<Data Name="LogonType">2</Data>
<Data Name="LogonProcessName">Advapi</Data>
<Data Name="AuthenticationPackageName">Negotiate</Data>
<Data Name="WorkstationName">REDACTED</Data>
<Data Name="TransmittedServices">-</Data>
<Data Name="LmPackageName">-</Data>
<Data Name="KeyLength">0</Data>
<Data Name="ProcessId">0x7a0</Data>
<Data Name="ProcessName">C:\Windows\System32\lsass.exe</Data>
<Data Name="IpAddress">-</Data>
<Data Name="IpPort">-</Data>
</EventData>
</Event>