Re: Account lockouts

From: Ole Kristian Bangås (ole_kristian_bangaas_at_hotmail.com)
Date: 01/16/05


Date: 16 Jan 2005 23:35:02 GMT


=?Utf-8?B?QkZU?= <BFT@discussions.microsoft.com> wrote in
news:AABB3C61-B400-4467-9AB4-435F5FA3C077@microsoft.com:

> I have a pretty big problem on my hands. I have account lockout
> occurring on my network. I fond a SAM error in my system log that I
> tracked down to an office over in Asia. I thought it might be a virus
> but was not. It seems to be some type of spy ware called
> securenet.exe anyway it looks like it uses the outlook address book
> and attempts to log on to active directory. Well I have my lockouts
> set and it locked accounts all week. I finally got the admin in that
> office to shut off those pc and reinstall them.
>
> Any way here is the real problem I had been unlocking accounts all
> week which equals thousands of unlocks. I printed my security log and
> the locks didn’t show up. Now all weekend I have been watching the
> security log and they seem to be appearing now.
>
> Has anyone ever had this problem and if so what can I do to stop the
> locks if the continue. I thought it might just be a backlog of active
> directory transactions. Any ideas im at a loss.

My first thought, since you apparently know the name of the executable,
is to greate a GPO denying that executable to run, and then start
cleaning up the system.

-- 
Ole Kristian Bangås


Relevant Pages

  • Re: Boot problems - How to debug / see an error message ?
    ... I would look in the System log and not the Security log. ... > up or this current successful boot up: ... > Alerter service, although I have so far failed to understand it. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: WINS could not start - Problem with logs
    ... The security log is full of Success Audit events ... >> Reading the system log is a problem. ... In management console reading the ... Clicking on the invisible list shows some events are empty ...
    (microsoft.public.backoffice.smallbiz2000)
  • Event View
    ... launch Event View, the system log displays with 16,226 ... however when I select security log of Application ... they show they are empty (sometimes security log will ... If I reselect system log, ...
    (microsoft.public.win2000.general)
  • Re: a forensic question
    ... As far as the workstation being "on" in the morning.... ... The System Log shows that the PC ... > actually turned off and on as he said, but the Security Log does not have ... > any entry concerning user logging in. ...
    (comp.security.misc)
  • Re: Kerberos event logging (LogLevel registry value)
    ... LogLevel refers to Kerberos logging in the SYSTEM log, ... > appear in the Security log, once the Account> Logon events auditing category is enabled). ...
    (microsoft.public.win2000.security)