I recently took over as the IT Manager and the old Manager’s account password has been changed, but I am still seeing logon attempts, successes and then an immediate logoff. The process using the user credentials is one of the svchost.exe processes. Does anyone have any idea why this is occurring? Is it safe to disable that account? Is there a way to find out why that process is using that user’s credentials.
Thanks in advance