(Windows XP/7 network)
Our Domain administrator accounts were being locked at first then User accounts were being locked out at random.
We started scanning the network with retina scanner and found infected computers. we patched these computers but we are still getting locked out. Retina returns values of computers being patched.
we are currently running a scheduled tasks to unlock accounts.
our antvirus program is finding 100’s of downadup hits on machines that are patched and running Trend micro offiicescan v 10.5.1799.
Are there any other ways of tracing down or isolating this virus?
Thank You