Windows AD accounts are looked out
Posted on 2010-03-29
There are lots of machines are infected by a virus/worm in our company, an antivirus pop-up message says: please reboot your machine to complete removing the viruses. After reboot the machine, user can log on and a pop-up message says “your account has been locked out".
Another problem is one of two domain controllers is producing lots TCP traffic (source port 139, destination IP is 172.16.11.x, destination port TCP 2xxx~32xxx) which has been blocked by our firewall. I have run our antivirus software and Malwarebytes' Anti-Malware on this domain controller (win2k3), and removed two virus infected files (one is WORM_DOWNAD.AD and another is MAl_DownadJ). The problem remains after reboot (lots traffic from this controller).
On some machines, users are unable to map any network drives, pop-up message says “can not access the network path..."
Is there anyone be able to tell us "How to" fix these problems.
Many thanks in advance.