Link to home
Start Free TrialLog in
Avatar of Sureshkumaar
SureshkumaarFlag for India

asked on

Security Alerts

Hi
we have got the below alert in our server monitoring
New Account Name (HelpAssistant_eefebe) has been added and deleted within 1 hour of Time frame on server .. i am unable to trace anything on the server. Please help me by giving more information about this and also on how to avoid this in future.

Thanks in advance
Suresh Techy.
Avatar of Murali
Murali
Flag of India image

Hi Suresh, What tool you use to monitor your network.. Is this Symantec Enterprise Security Manger??
HelpAssistant is the default windows account name.. and eefebe should be your computer name.. this account is default you dont have to do any on it.. let it be...

You need to exclude/suppress this account not for this alert...
Avatar of Sureshkumaar

ASKER

Hi Murali

monitoring is being done by other team who are specialists in ISMS. and the computer name is not eefebe. could i get more details on this. I googled and found no info is satisfying.

For what help assistants are used? Why it should create and delete the user id's on its own?

Sureshtechy.
Hi Suresh.. actally i can tell you how this alert has been throuwn by your secuirty monitoring system...

these security monitoring systems will record the system state everytime.... typically these are called snapshots.. and they will have schedule running.. everyday or everyweek.. when it runs initially it captures all security settings of machine like usrs, groups, membership, local security policy and etc...

when the next schedule runs.. it captures and compares with preview snapshot.. whatever difference found .. based on category like users or security policy it will assign the critically and throgh the alert..

at this point of time you can tel your security team that.. this is default windows account.. no account has been created.. it is been there from the time of windows installed.. so exclude this user from the check...

and also you question back them... why you are alerting you on this.. bcoz it is been there from long time.. why now the security system is alerting me about it.. is it not somethign wrong from their end???
Check this article if you have this problem for xp home/prof

http://support.microsoft.com/kb/323647
ASKER CERTIFIED SOLUTION
Avatar of Russell_Venable
Russell_Venable
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial