net.exe file triggered every minute

Anonymous
2024-10-04T10:51:33+00:00

Hello,

     I have an issue with my windows server 2016, we are using crowdstrike antivirus but shows a detection net.exe every minute, actually by using net.exe someone or some thing in background run a command as net localgroup "administrators" Guest/add by triggering this command every minute i can't able to disable the Guest account If i rename or delete the account it will recreate while command triggering. i check with startup and task scheduler also there is no program running, Please someone told me how to stop that net command triggering.
Windows Server Remote and virtual desktops

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question. To protect privacy, user profiles for migrated questions are anonymized.

0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2024-10-08T01:47:20+00:00

    Hello,

    The most straightforward approach is to identify the source of the command. Use Process Monitor  to capture real-time file system, registry, and process/thread activity. Apply a filter for net.exe to see what is triggering it.

    Additionally, perform a full system scan with CrowdStrike and consider using Windows Defender to ensure that no malware is present.

    Best Regards, Karlie Weng

    0 comments No comments