Steve,
I run Proccess Monitor and I see nothing with my user. The only thing that's I have is:
1:45:03.8284555 PM lsass.exe 492 RegOpenKey HKLM\SAM\SAM\DOMAINS\Account\Users\Names\any SUCCESS NT AUTHORITY\SYSTEM 09/10/2009 1:45:03 PM
1:45:03.8285213 PM lsass.exe 492 RegQueryValue HKLM\SAM\SAM\Domains\Account\Users\Names\any\(Default) SUCCESS Type: <Unknown: 1100>, Length: 0 NT AUTHORITY\SYSTEM 09/10/2009 1:45:03 PM
1:45:03.8285866 PM lsass.exe 492 RegCloseKey HKLM\SAM\SAM\Domains\Account\Users\Names\any SUCCESS NT AUTHORITY\SYSTEM 09/10/2009 1:45:03 PM
I see that in the system log:
Event Type: Warning
Event Source: MSFTPSVC
Event Category: None
Event ID: 100
Date: 09/10/2009
Time: 1:45:03 PM
User: N/A
Computer: ServerName
Description:
The server was unable to logon the Windows NT account 'any' due to the following error: The specified procedure could not be found. The data is the error code.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 7f 00 00 00
Thanks
David