Solved

Windows 2008 Errors

Posted on 2013-01-22
7
406 Views
Last Modified: 2013-01-22
I have a Windows 2008 domain contoller & it has started throwing numerous event ID 12294:

The SAM database was unable to lockout the account of Administrator due to a resource error, such as a hard disk write failure (the specific error code is in the error data) . Accounts are locked after a certain number of bad passwords are provided so please consider resetting the password of the account mentioned above.


This server is also a FSMO role holder & a WSUS server. Has anyone seen this? I rebooted the server & it is still doing this...any ideas?
0
Comment
Question by:wantabe2
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 11

Expert Comment

by:Venugopal N
ID: 38805447
0
 
LVL 15

Author Comment

by:wantabe2
ID: 38805486
Doesn't help any...can't disable the admin account.
0
 
LVL 14

Accepted Solution

by:
BlueCompute earned 500 total points
ID: 38805553
The error message is misleading - the reason the SAM database was unable to lock out the account is not a resource error, it is because the Administrator account cannot be locked out - you'd be stuffed if it was your last administrator account and it got locked out.

This is usually a sign that the server is subject to a brute-force attack - what services do you have exposed to the internet?  RDP, Exchange, IIS?  You should be able to confirm this by looking in the security log for a large number of authentication failures for the administrator account.
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 
LVL 15

Author Comment

by:wantabe2
ID: 38805615
There are no services as such exposed to eh outside world. This is just an internal LAN server that holds the following roles:

WSUS, Domain Controller, DNS server

I've ran a full virus scan & found nothing. There are no authentication failures in the security log. Still getting there same event around 4 or 5 events per minute.
0
 
LVL 15

Author Comment

by:wantabe2
ID: 38805665
I've looked in the netlogon.log file to see if there where any clients trying to log on as the administrator but I see no bad password logged....
0
 
LVL 18

Expert Comment

by:Sarang Tinguria
ID: 38806791
Follow this

Troubleshooting Account Lockout
http://technet.microsoft.com/en-us/library/cc773155(v=ws.10).aspx

Troubleshooting account lockout the PSS way
http://blogs.technet.com/b/instan/archive/2009/09/01/troubleshooting-account-lockout-the-pss-way.aspx

Below link is of specific tool which removes the Kido Virus found majorly producing such issues

http://support.kaspersky.com/1956
Go to "Protection measures":->kk.zip

You may check security event logs if auditing is enable to see which machine is generating bad password requests
0
 
LVL 15

Author Closing Comment

by:wantabe2
ID: 38806968
I checked the log & discovered which clinet was trying to authenticate to the DC.
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
Uncontrolled local administrators groups within any organization pose a huge security risk. Because these groups are locally managed it becomes difficult to audit and maintain them.
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question