We have one system running Windows 7 Professional that logs a security audit failure with an error code of C0000072 (account is currently disabled) dozens of times a day. The user name listed is the local guest account, which has been disabled. Is there a way for us to determine what is trying to use the local guest account, in other words, what is causing the audit failure entries? Thanks.