im not really sure by looking at the eventlog but there's a few worms that attack the nt login prococess (lsass) like blaster and a few public autohaxors (that dont cause a re-boot) but if your up to date on patches i wouldn't worry too much about that.
if this is the only attemt you've found like this its definitly not someone trying to hack you. you would find more than one. its probably just a worm 'passing by'. it wouldnt hurt to check for successful logins as well.
attached is something i use to make this process easier. it will dump your security, application and system logs to a file and pop up the results as a web page. just run dump.bat




Reply With Quote