On a W2K Advanced Server with Terminal Services, I am auditing successful and failed logins. In that log, roughly half of the audited logons are: NT AUTHORITY\ANONYMOUS LOGON. They seem to only be making successful LOGOFF entries, no LOGON entries. What is causing these, are they normal, is there any way to stop them?