|Subject:||User named "microsoft" in administrators group|
|Posted by:||OscarArg (OscarA…@discussions.microsoft.com)|
|Date:||Wed, 22 Jul 2009|
In one of our 2003 servers, I find that there exists a user "microsoft"
which belongs to the Administrators group, and is running logon.scr (using
sysinternals process explorer). Is this normal or some kind of trojan? I've
never seen it before.