Administrator accounting being locked out

darren

Distinguished
Jun 26, 2003
131
0
18,680
Archived from groups: microsoft.public.win2000.general (More info?)

There is some process which keeps locking the admin account. Is there some
tool on the market to help me find what is doing this. The event log only
shows the following:


Reason: Unknown user name or bad password
User Name: Administrator
Domain: @@@@@@@
Logon Type: 4
Logon Process: Advapi
Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0

I checked all the services passwords and they seem correct.
 

CD

Distinguished
May 1, 2004
87
0
18,630
Archived from groups: microsoft.public.win2000.general (More info?)

A quick search on the advapi.exe process revealed this:

advapi.exe is added as a result of the NETDEVIL.12 (NetDevil 1.2) VIRUS.
This process is a security risk and should be removed from your system. If
found make sure that you have downloaded the latest updates for your
antivirus software..

Looks like you may want to scan your system with up to date virus scan and
spyware/malware programs.

"Darren" wrote:

> There is some process which keeps locking the admin account. Is there some
> tool on the market to help me find what is doing this. The event log only
> shows the following:
>
>
> Reason: Unknown user name or bad password
> User Name: Administrator
> Domain: @@@@@@@
> Logon Type: 4
> Logon Process: Advapi
> Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
>
> I checked all the services passwords and they seem correct.
>
>
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.general (More info?)

From: "Darren" <Darren@discussions.microsoft.com>

| There is some process which keeps locking the admin account. Is there some
| tool on the market to help me find what is doing this. The event log only
| shows the following:
|
| Reason: Unknown user name or bad password
| User Name: Administrator
| Domain: @@@@@@@
| Logon Type: 4
| Logon Process: Advapi
| Authentication Package: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
|
| I checked all the services passwords and they seem correct.
|


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm