following messages appearing in event viewer.
User changed password due to domain policy and has had
this problem since. The server name can be any server on
our network.

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40961
Date: 10/07/2003
Time: 11:25:15
User: N/A
Computer: HIGGS
Description:
The Security System could not establish a secured
connection with the server cifs/orchid. No
authentication protocol was available.

Event Type: Warning
Event Source: LSASRV
Event Category: SPNEGO (Negotiator)
Event ID: 40960
Date: 10/07/2003
Time: 14:55:35
User: N/A
Computer: HIGGS
Description:
The Security System detected an attempted downgrade
attack for server LDAP/****.prophet.co.uk. The failure
code from authentication protocol Kerberos was "The user
account has been automatically locked because too many
invalid logon attempts or password change attempts have
been requested.
(0xc0000234)".