user named "microsoft" in administrators group
Hello
In one of our 2003 servers, I find that there exists a user "microsoft"
which belongs to the Administrators group, and is running logon.scr (using
sysinternals process explorer). Is this normal or some kind of trojan? I've
never seen it before.
TIAoscar
July 22nd, 2009 11:15pm
It is not created by Windows as part of a normal install. However, I cannot speculate on what might have created it and what it is doing. I would investigate by checking what the script does, and what permissions it has, as well as checking to see who or what service uses that account to logon.Dave Bishop
Senior Technical Writer
Windows Server Networking User Assistance
Free Windows Admin Tool Kit Click here and download it now
July 23rd, 2009 12:44am


