Hi all, my admin account keeps getting locked out every 10 to 15 mins (recently changed my password). I have no manually mapped drives,
no cached login infor in keymgr.cpl and none of the services are configured to
use my admin account (we have seperate service account). I also checked all object in DCOM and non use my
account.
Here is the output received from Alockout.txt utility
Please Help..........
Fri Sep 24 10:58:28 2010, PID: 17760, Thread: 14432, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 10:58:35 2010, PID: 17760, Thread: 14432, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:00:00 2010, PID: 17660, Thread: 17764, Image cmd.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:00:02 2010, PID: 17660, Thread: 17764, Image cmd.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:03:14 2010, PID: 13792, Thread: 18408, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:07:48 2010, PID: 13792, Thread: 18408, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:18:15 2010, PID: 14988, Thread: 10728, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:22:51 2010, PID: 14988, Thread: 10728, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:28:32 2010, PID: 16668, Thread: 17192, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:28:39 2010, PID: 16668, Thread: 17192, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:30:00 2010, PID: 16636, Thread: 13664, Image cmd.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:30:02 2010, PID: 16636, Thread: 13664, Image cmd.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:33:16 2010, PID: 16556, Thread: 18336, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:37:55 2010, PID: 16556, Thread: 18336, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:48:16 2010, PID: 17016, Thread: 11780, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:52:58 2010, PID: 17016, Thread: 11780, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 11:58:36 2010, PID: 11388, Thread: 17064, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 11:58:43 2010, PID: 11388, Thread: 17064, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:00:00 2010, PID: 17312, Thread: 17724, Image cmd.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:00:12 2010, PID: 17312, Thread: 17724, Image cmd.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:03:17 2010, PID: 17252, Thread: 18284, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:08:05 2010, PID: 17252, Thread: 18284, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:18:17 2010, PID: 17756, Thread: 18280, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:23:08 2010, PID: 17756, Thread: 18280, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:28:38 2010, PID: 15540, Thread: 15468, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:28:45 2010, PID: 15540, Thread: 15468, Image C:\Program Files\Symantec AntiVirus\SescLU.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:30:00 2010, PID: 15440, Thread: 17184, Image cmd.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:30:02 2010, PID: 15440, Thread: 17184, Image cmd.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:33:18 2010, PID: 9268, Thread: 16724, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Sep 24 12:38:12 2010, PID: 9268, Thread: 16724, Image C:\WINNT\system32\wbem\wmiprvse.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Sep 24 12:41:03 2010, PID: 16500, Thread: 16420, Image C:\WINNT\system32\mmc.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH