- For individual users
- Instant access to solutions
- Ask your tech questions
- Start your 30-day Free Trial
Main Topics
Browse All TopicsAn account on our domain is getting locked out quiet frequently. I've implemented the alockout.txt file and this is the output. I'm trying to figure out where the issue lies. Can someone help me interpret?
Fri Mar 13 07:27:19 2009, PID: 1304, Thread: 1308, Image winlogon.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:27:20 2009, PID: 1348, Thread: 1352, Image C:\WINDOWS\system32\servic
Fri Mar 13 07:27:20 2009, PID: 1360, Thread: 1364, Image C:\WINDOWS\system32\lsass.
Fri Mar 13 07:27:21 2009, PID: 1520, Thread: 1524, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:27:21 2009, PID: 1600, Thread: 1604, Image C:\WINDOWS\system32\EMSSer
Fri Mar 13 07:27:26 2009, PID: 1676, Thread: 1680, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:27:26 2009, PID: 1872, Thread: 1876, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:27:26 2009, PID: 1904, Thread: 1908, Image C:\WINDOWS\system32\CmgShi
Fri Mar 13 07:27:32 2009, PID: 376, Thread: 380, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:27:32 2009, PID: 428, Thread: 432, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:27:33 2009, PID: 784, Thread: 788, Image C:\WINDOWS\system32\spools
Fri Mar 13 07:27:47 2009, PID: 1428, Thread: 1432, Image C:\Program Files\Altiris\AClient\ACli
Fri Mar 13 07:27:47 2009, PID: 1560, Thread: 1564, Image c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe,ALOCKOUT.
Fri Mar 13 07:27:47 2009, PID: 1736, Thread: 1740, Image C:\WINDOWS\system32\QosSer
Fri Mar 13 07:27:47 2009, PID: 1776, Thread: 1780, Image C:\Program Files\Network Associates\Common Framework\FrameworkService
Fri Mar 13 07:27:51 2009, PID: 1488, Thread: 2036, Image C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe,AL
Fri Mar 13 07:27:53 2009, PID: 348, Thread: 356, Image C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE,AL
Fri Mar 13 07:27:57 2009, PID: 580, Thread: 616, Image C:\Program Files\lotus\notes\ntmulti.
Fri Mar 13 07:27:59 2009, PID: 964, Thread: 352, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:27:59 2009, PID: 1016, Thread: 1020, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:28:00 2009, PID: 1144, Thread: 1148, Image C:\WINDOWS\system32\locato
Fri Mar 13 07:28:00 2009, PID: 1180, Thread: 1184, Image c:\Program Files\Cisco Systems\VPN Client\vpngui.exe,ALOCKOUT
Fri Mar 13 07:28:01 2009, PID: 1424, Thread: 168, Image c:\windows\system32\slclie
Fri Mar 13 07:28:03 2009, PID: 1840, Thread: 1848, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:28:04 2009, PID: 1968, Thread: 2028, Image c:\Program Files\Cisco Systems\VPN Client\ipseclog.exe,ALOCKO
Fri Mar 13 07:28:05 2009, PID: 1520, Thread: 1588, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:28:06 2009, PID: 464, Thread: 492, Image C:\WINDOWS\system32\wbem\w
Fri Mar 13 07:28:20 2009, PID: 1304, Thread: 1420, Image winlogon.exe,***StartServi
Fri Mar 13 07:28:27 2009, PID: 1968, Thread: 2028, Image c:\Program Files\Cisco Systems\VPN Client\ipseclog.exe,ALOCKO
Fri Mar 13 07:28:27 2009, PID: 1180, Thread: 1184, Image c:\Program Files\Cisco Systems\VPN Client\vpngui.exe,ALOCKOUT
Fri Mar 13 07:28:34 2009, PID: 712, Thread: 716, Image mpnotify.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:28:43 2009, PID: 696, Thread: 700, Image C:\WINDOWS\system32\WgaTra
Fri Mar 13 07:28:43 2009, PID: 696, Thread: 700, Image C:\WINDOWS\system32\WgaTra
Fri Mar 13 07:28:45 2009, PID: 1864, Thread: 2940, Image cmd,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:28:45 2009, PID: 412, Thread: 1048, Image C:\ScriptLogic\SLstart.exe
Fri Mar 13 07:28:47 2009, PID: 2060, Thread: 2064, Image C:\ScriptLogic\slagent.exe
Fri Mar 13 07:28:47 2009, PID: 2068, Thread: 2072, Image C:\WINDOWS\system32\wuaucl
Fri Mar 13 07:28:51 2009, PID: 2324, Thread: 2320, Image C:\WINDOWS\system32\slagen
Fri Mar 13 07:28:51 2009, PID: 2324, Thread: 2320, Image C:\WINDOWS\system32\slagen
Fri Mar 13 07:28:52 2009, PID: 2352, Thread: 2364, Image C:\WINDOWS\system32\slagen
Fri Mar 13 07:28:52 2009, PID: 2352, Thread: 2364, Image C:\WINDOWS\system32\slagen
Fri Mar 13 07:28:52 2009, PID: 2060, Thread: 2064, Image C:\ScriptLogic\slagent.exe
Fri Mar 13 07:28:55 2009, PID: 2440, Thread: 2444, Image C:\WINDOWS\system32\slagen
Fri Mar 13 07:28:58 2009, PID: 2572, Thread: 2576, Image C:\ScriptLogic\wkix32.exe,
Fri Mar 13 07:29:18 2009, PID: 1840, Thread: 1916, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:29:20 2009, PID: 3428, Thread: 3432, Image net,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:21 2009, PID: 3456, Thread: 3460, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:22 2009, PID: 3456, Thread: 3460, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:22 2009, PID: 3428, Thread: 3432, Image net,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:37 2009, PID: 3584, Thread: 3588, Image cmd,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:38 2009, PID: 3648, Thread: 3652, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:39 2009, PID: 3660, Thread: 3656, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:39 2009, PID: 3660, Thread: 3656, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:39 2009, PID: 3648, Thread: 3652, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:40 2009, PID: 3664, Thread: 3668, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:41 2009, PID: 3676, Thread: 3680, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:41 2009, PID: 3676, Thread: 3680, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:41 2009, PID: 3664, Thread: 3668, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:43 2009, PID: 3692, Thread: 3688, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:44 2009, PID: 3696, Thread: 3700, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:44 2009, PID: 3696, Thread: 3700, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:44 2009, PID: 3692, Thread: 3688, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:44 2009, PID: 3704, Thread: 3708, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:44 2009, PID: 3712, Thread: 3716, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:44 2009, PID: 3712, Thread: 3716, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:45 2009, PID: 3704, Thread: 3708, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:45 2009, PID: 3724, Thread: 3720, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:45 2009, PID: 3732, Thread: 3736, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:45 2009, PID: 3732, Thread: 3736, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:45 2009, PID: 3724, Thread: 3720, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:46 2009, PID: 3740, Thread: 3744, Image net.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:46 2009, PID: 3748, Thread: 3756, Image net1,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:46 2009, PID: 3748, Thread: 3756, Image net1,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:46 2009, PID: 3740, Thread: 3744, Image net.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:46 2009, PID: 3584, Thread: 3588, Image cmd,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:48 2009, PID: 3820, Thread: 1340, Image cmd,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:29:49 2009, PID: 3820, Thread: 1340, Image cmd,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:29:52 2009, PID: 3904, Thread: 3932, Image cmd,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:30:04 2009, PID: 980, Thread: 828, Image xcopy,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:30:07 2009, PID: 2572, Thread: 2576, Image C:\ScriptLogic\wkix32.exe,
Fri Mar 13 07:30:08 2009, PID: 412, Thread: 1048, Image C:\ScriptLogic\SLstart.exe
Fri Mar 13 07:30:08 2009, PID: 1864, Thread: 2940, Image cmd,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:30:15 2009, PID: 1136, Thread: 1140, Image C:\WINDOWS\Explorer.EXE,Us
Fri Mar 13 07:30:17 2009, PID: 2192, Thread: 2204, Image C:\Program Files\Java\j2re1.4.2_14\bi
Fri Mar 13 07:30:18 2009, PID: 2192, Thread: 2204, Image C:\Program Files\Java\j2re1.4.2_14\bi
Fri Mar 13 07:30:20 2009, PID: 2076, Thread: 624, Image C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE,ALOC
Fri Mar 13 07:30:21 2009, PID: 2180, Thread: 2176, Image C:\Program Files\Network Associates\Common Framework\UdaterUI.exe,ALO
Fri Mar 13 07:30:23 2009, PID: 2484, Thread: 2544, Image C:\Program Files\Tools4ever\SSRPM\Enr
Fri Mar 13 07:30:24 2009, PID: 2660, Thread: 2680, Image C:\WINDOWS\system32\imapi.
Fri Mar 13 07:30:25 2009, PID: 2784, Thread: 2792, Image /load,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:30:25 2009, PID: 1520, Thread: 1588, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:30:26 2009, PID: 2808, Thread: 2480, Image C:\WINDOWS\system32\wbem\w
Fri Mar 13 07:30:27 2009, PID: 2968, Thread: 3032, Image C:\WINDOWS\system32\ctfmon
Fri Mar 13 07:30:27 2009, PID: 1520, Thread: 1868, Image C:\WINDOWS\system32\svchos
Fri Mar 13 07:30:29 2009, PID: 2984, Thread: 2300, Image C:\Program Files\Cisco Systems\VPN Client\vpngui.exe,ALOCKOUT
Fri Mar 13 07:30:32 2009, PID: 3964, Thread: 3972, Image c:\Program Files\Cisco Systems\VPN Client\ipseclog.exe,ALOCKO
Fri Mar 13 07:30:33 2009, PID: 2660, Thread: 2680, Image C:\WINDOWS\system32\imapi.
Fri Mar 13 07:31:05 2009, PID: 980, Thread: 828, Image xcopy,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:31:05 2009, PID: 3904, Thread: 3932, Image cmd,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:31:40 2009, PID: 3552, Thread: 888, Image NLNOTES.EXE,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:31:41 2009, PID: 3536, Thread: 3560, Image C:\Program Files\lotus\notes\nfileret
Fri Mar 13 07:31:44 2009, PID: 3596, Thread: 3600, Image C:\Program Files\lotus\notes\NCDaemon
Fri Mar 13 07:31:53 2009, PID: 3536, Thread: 3560, Image C:\Program Files\lotus\notes\nfileret
Fri Mar 13 07:31:56 2009, PID: 464, Thread: 492, Image C:\WINDOWS\system32\wbem\w
Fri Mar 13 07:32:02 2009, PID: 3624, Thread: 3040, Image C:\Program Files\lotus\notes\ndyncfg.
Fri Mar 13 07:32:03 2009, PID: 3624, Thread: 3040, Image C:\Program Files\lotus\notes\ndyncfg.
Fri Mar 13 07:32:05 2009, PID: 3308, Thread: 1816, Image wmiadap.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:32:20 2009, PID: 1092, Thread: 1672, Image C:\Program Files\lotus\notes\ntaskldr
Fri Mar 13 07:32:20 2009, PID: 3308, Thread: 1816, Image wmiadap.exe,ALOCKOUT.DLL - dll_process_detatch
Fri Mar 13 07:34:02 2009, PID: 2152, Thread: 2160, Image C:\WINDOWS\system32\wbem\w
Fri Mar 13 07:35:32 2009, PID: 2152, Thread: 2160, Image C:\WINDOWS\system32\wbem\w
Fri Mar 13 07:39:03 2009, PID: 2068, Thread: 2072, Image C:\WINDOWS\system32\wuaucl
Fri Mar 13 07:48:02 2009, PID: 424, Thread: 2952, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:50:06 2009, PID: 424, Thread: 172, Image C:\WINDOWS\System32\svchos
Fri Mar 13 07:51:25 2009, PID: 3800, Thread: 3804, Image C:\Program Files\lotus\notes\ndyncfg.
Fri Mar 13 07:51:26 2009, PID: 3800, Thread: 3804, Image C:\Program Files\lotus\notes\ndyncfg.
Fri Mar 13 07:51:51 2009, PID: 1816, Thread: 3308, Image C:\WINDOWS\system32\rsvp.e
Fri Mar 13 07:52:00 2009, PID: 2688, Thread: 2532, Image mstsc.exe,ALOCKOUT.DLL - DLL_PROCESS_ATTACH
Fri Mar 13 07:58:01 2009, PID: 3692, Thread: 816, Image C:\WINDOWS\System32\svchos
Fri Mar 13 08:00:04 2009, PID: 3692, Thread: 3940, Image C:\WINDOWS\System32\svchos
Fri Mar 13 08:02:24 2009, PID: 2520, Thread: 3276, Image C:\Program Files\LogMeIn Rescue Calling Card\CallingCard.exe,ALOCK
Fri Mar 13 08:03:14 2009, PID: 696, Thread: 3412, Image C:\Program Files\LogMeIn Rescue Calling Card\CallingCard.exe,ALOCK
Fri Mar 13 08:04:56 2009, PID: 460, Thread: 2900, Image C:\WINDOWS\system32\NOTEPA
Fri Mar 13 08:06:30 2009, PID: 460, Thread: 2900, Image C:\WINDOWS\system32\NOTEPA
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: LingerLongerPosted on 2009-03-13 at 11:47:51ID: 23882387
Usually, this is a result of a service being configured to run as the user in question, or another computer on the network still being logged in with the incorrect credentials (trying to repeatedly send them to Exchange for example in the background). ows/ Removi ng_cached_ credential s.htm. Check for any cached credentials with this user's domain account, as this could be trying against a persistent drive mapping or similar.
Check services on the local computer to see if anything is running as the user, check a domain controller for sessions by the user from a computer other than the one you think they're on. Also try this - http://www.shijaz.com/wind