There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu graphics hard drive hardware hdmi internet laptop malware memory monitor motherboard mouse network printer problem ram registry router server slow software sound svchost.exe trojan usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
monitoring user log in

Reply  
Thread Tools
SepiasSoul's Avatar
Computer Specs
Member with 262 posts.
 
Join Date: Jan 2005
Experience: Depends on subject area i guess
29-Dec-2008, 08:06 PM #1
monitoring user log in
Ive recently run into an issue at work where the files on my PC, as well as several other employees have had files go missing or being moved into different location, and email being read and forwarded mysteriously. The upper management seems to be of the belief that someone is logging into the accounts and reading some of the more sensitive information on the computers, they are of the belief that it may be the IT department since they have access to all the computers on an administrative level. I was wondering if there was any software out there that would create a log of user log ins, dates and times for the log ins on the affected PC's. If it could record the actions that are being done, that would be a plus, but all we really need is proof that someone is loging in and how so we could lock them down, and prevent it in the future. I appreciate the help.

Sepias
lunarlander's Avatar
Computer Specs
Senior Member with 3,484 posts.
 
Join Date: Sep 2007
29-Dec-2008, 08:29 PM #2
There are logs of people logging in in the event viewer. It is at Start > Administrative Tools > Event Viewer.

If you don't see Administrative Tools, then you need to right click on the Start button > Properties > Start menu customize. And enable "System Administrative Tasks" near the bottom of the scroll list. ( Mine is a Vista box, the wording might be a little different on XP )

Then you look for these Event IDs ( for Vista) :
4624,4636 for all logins.
4672 for admin logins

For XP, the Event IDs are :
528/540 for all login
576 for admin logins

However, if they are logging in as admins, they can erase the security log.

Last edited by lunarlander; 29-Dec-2008 at 08:35 PM..
SepiasSoul's Avatar
Computer Specs
Member with 262 posts.
 
Join Date: Jan 2005
Experience: Depends on subject area i guess
10-Jan-2009, 01:17 PM #3
sorry it took me so long to reply. Yes the logs have been erased. Is there an outside program that you know of that can log events? Preferably one that can be installed on the local machine? Aside from that, I take it encryption is my only other option for the files, or taking the PC's off the network am I correct? Since the IT department says the need administrative access to all the PCs, restricting them isn't an option.

Thanks for the reply.
lunarlander's Avatar
Computer Specs
Senior Member with 3,484 posts.
 
Join Date: Sep 2007
15-Jan-2009, 05:46 PM #4
I dont know of any third party programs that can record logins. I think encryption is your only choice. Have a look at Truecrypt, it is free and pretty good.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:33 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.