On 20 Sep 01, at 10:11, Birl wrote:
> Does anyone know how this folder may have been created?
These folders will be created for every user who logs on locally (which
might be at the console or as a service)
Computername$ is the hidden account for the machine used when logging on at
the domain controller.
When this account is created, it has a well known password (but I don't
remember it now ;) which will be changed soon and every week afterwards.
In theory, somebody who knows the password (sniffing on LAN and cracking
it), probably could have used this username/password combination to log on
at the machine locally.
You just need to search security event 528 (logon type 2 and 4) for this
account.
Greetings
Frank Heyne