Hello OscarArg,
No that's not normal. I would immediately disable that account and check
where it is used and who has created that.
Best regards
Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!!
http://www.blakjak.demon.co.uk/mul_crss.htm
> Hello
> In one of our 2003 servers, I find that there exists a user
> "microsoft"
> which belongs to the Administrators group, and is running logon.scr
> (using
> sysinternals process explorer). Is this normal or some kind of trojan?
> I've
> never seen it before.
> TI