user named "microsoft" in administrators group
Hello In one of our 2003 servers, I find that there exists a user "microsoft" which belongs to the Administrators group, and is running logon.scr (using sysinternals process explorer). Is this normal or some kind of trojan? I've never seen it before. TIAoscar
July 22nd, 2009 11:15pm

It is not created by Windows as part of a normal install. However, I cannot speculate on what might have created it and what it is doing. I would investigate by checking what the script does, and what permissions it has, as well as checking to see who or what service uses that account to logon.Dave Bishop Senior Technical Writer Windows Server Networking User Assistance
Free Windows Admin Tool Kit Click here and download it now
July 23rd, 2009 12:44am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics